101 Malicious npm Packages Exploit Baileys to Unauthorizedly Add Developers to WhatsApp Groups
Cybersecurity researchers identified 101 malicious npm packages leveraging the Baileys WhatsApp framework to secretly add developers to unauthorized groups. The packages, distributed through three variants, exploit WhatsApp bot sessions to subscribe users to attacker-controlled channels, with some groups linked to Indonesian mobile game and app promotions.
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub.
"The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical
*** END OF TRANSMISSION ***