PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels

PhantomSub: 101 Malicious npm Baileys Forks Force (TL-2026-2785), also tracked as PhantomSub, is a medium-severity supply-chain compromise, first published 2026-09-29. It has no confirmed attribution, affects npm ecosystem Baileys WhatsApp library forks (101 malicious packages), maps to 8 MITRE ATT&CK techniques (T1027, T1036.005, T1059.007), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-2785

Threat ID
TL-2026-2785
Also known as
PhantomSub
Severity
MEDIUM
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
2026-09-29
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, software-development
Target regions
Global, Southeast Asia
Detection rules
9
Indicators of compromise
29

Malware and tooling in PhantomSub: 101 Malicious npm Baileys Forks Force

Malware and tooling: newsletter JID 120363406068468165@newsletter, newsletter JID 120363418582531215@newsletter, newsletter JID 120363420514587725@newsletter, newsletter JID 120363426706961217@newsletter

PhantomSub is a supply-chain campaign of 101 malicious npm packages that are modified forks of the Baileys WhatsApp library. At runtime they use the developer's authenticated WhatsApp session to follow attacker-chosen channels and join attacker-chosen groups without consent, and they inject promotional URLs into bot-sent media. The packages total about 490,000 downloads, 116,000 of them in the last 30 days.

How PhantomSub: 101 Malicious npm Baileys Forks Force works

OX Security (Nir Zadok, Moshe Siman Tov Bustan, Vitalii Chepurko) reported PhantomSub on 2026-09-29 as 101 npm packages that copy the open-source Baileys WhatsApp Web API library (@whiskeysockets/baileys). The forks keep the library's API so they work as drop-in replacements for developers building WhatsApp bots. The added code acts inside the developer's already-authenticated WhatsApp session. It adds the account to attacker-controlled groups and channels without consent, and it injects promotional URLs into media the bot sends. The reporting describes promotion of game accounts, bot scripts, premium APKs and social-media boosting services, mostly Indonesian-oriented.

OX Security identified three implementation variants. In variant 1 (19 packages) the target channel IDs are fetched from GitHub at runtime. In variant 2 (60 packages) the channel IDs are embedded in cleartext in the source. In variant 3 (14 packages) the channel IDs are embedded in encoded or obfuscated form. The article's variant counts sum to 93, not 101, so the split for the remaining packages is not stated. Identified targets are the WhatsApp groups/channels Neural (798 followers, resource supplies marketplace), MONTE - BMG (1,000), CORTANA TECH (1,300) and Fyxzpedia.ID - Utama (4,800).

Independent per-package analyses (OSV MAL advisories, Xygeni, OffSeq/hacktron) show the shared mechanism. The injection sits in library socket/newsletter code (lib/Socket/newsletter.js, or lib/Socket/socket.js for chromestaff-baileys). It runs after module load or connection, not at install time. It fires after a delay: 80 seconds for @dappaoffc/baileys-mod, 120 seconds for my-auto-follow and 200 seconds for @fyxzpediaa/baileys. It then fetches a JSON list of newsletter JIDs from an attacker-controlled raw.githubusercontent.com file, or reads hardcoded JIDs, and calls the library's internal newsletter follow query (newsletterWMexQuery with QueryIds.FOLLOW, or followNewsletterWMex). Errors are swallowed silently. Because the list is remote, the attacker can retarget without republishing. Some forks also alias the libsignal dependency to a malicious variant (@skyzopedia/libsignal-node) and use unpinned git dependencies.

Timeline per the sources: SafeDep disclosed the initial malicious Baileys fork behaviour in August 2026, Xygeni disclosed @dappaoffc/baileys-mod in early September 2026, and OX Security published the consolidated PhantomSub analysis on 2026-09-29. The sources do not report credential theft, persistence or host code execution. The documented impact is loss of control over the account's group/channel membership and social-graph actions, and use of the developer's identity for promotion. Severity is an analyst judgement (MEDIUM) because no CVE or CVSS exists. Only the single OX/The Hacker News article was verified for campaign-wide numbers, since the OX, SafeDep and Xygeni primary campaign reports were not directly retrievable. The per-package technical detail comes from OSV, Xygeni and OffSeq/hacktron pages.

MITRE ATT&CK techniques used in TL-2026-2785

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1497.003 Time Based Checks

Execution

T1059.007 JavaScript

Command and Control

T1102.001 Dead Drop Resolver

Initial Access

T1195.001 Compromise Software Dependencies and Development Tools

Impact

T1565.002 Transmitted Data Manipulation

Resource Development

T1583.006 Web Services

Affected products and versions in PhantomSub: 101 Malicious npm Baileys Forks Force

  • npm ecosystem — Baileys WhatsApp library forks (101 malicious packages)
    Vulnerable versions: chromestaff-baileys 1.1.3; my-auto-follow 1.0.0-1.0.3, 1.0.6, 1.0.7; @fyxzpediaa/baileys 8.1.2, 9.1.0; @dappaoffc/baileys-mod 8.0.1; naileys 0.5.2

Remediation for PhantomSub: 101 Malicious npm Baileys Forks Force

Immediate actions

  • Search lockfiles and package.json for the listed Baileys-fork package names and remove them
  • Reinstall the official @whiskeysockets/baileys from a pinned, verified release
  • Review WhatsApp groups and followed channels on bot accounts and leave or block unauthorized ones (Neural, MONTE - BMG, CORTANA TECH, Fyxzpedia.ID - Utama)
  • Inspect lib/Socket/newsletter.js and lib/Socket/socket.js in installed forks for fetch() calls to raw.githubusercontent.com and newsletter FOLLOW queries

Workarounds

  • Egress-monitor build and bot hosts for unexpected raw.githubusercontent.com requests originating from the WhatsApp socket process

Longer-term hardening

  • Pin dependencies and use lockfiles; avoid git+https or mutable tarball dependencies and npm aliases such as libsignal to unvetted packages
  • Use software composition analysis or malicious-package feeds (OSV MAL advisories) in CI
  • Avoid linking personal WhatsApp accounts to third-party forks; use a dedicated bot account

Weaknesses (CWE) in PhantomSub: 101 Malicious npm Baileys Forks Force

CWE-506

Timeline of PhantomSub: 101 Malicious npm Baileys Forks Force

  • OSV record MAL-2026-4519 for chromestaff-baileys 1.1.3, which forces a follow of newsletter 120363418582531215@newsletter, carries a status date of 2026-05-26 (listed as withdrawn). Amazon Inspector is credited as the discoverer.
  • SafeDep disclosed the initial malicious Baileys fork behaviours (August 2026; exact day not stated in the source).
  • my-auto-follow was published; it waits 120 seconds after session start, then fetches newsletter JIDs from DGXeon13/strings on GitHub and follows each one.
  • Xygeni Security disclosed @dappaoffc/baileys-mod (v8.0.1), which fetches idChannel.json from the skyzopedia/Screaper GitHub repo 80 seconds after load (early September 2026; exact day not stated).
  • @fyxzpediaa/baileys 8.1.2 and 9.1.0 were published; they rebuild an obfuscated URL to skyzopedia/NewsletterID VIP_Push.json and query it 200 seconds after connection.
  • OX Security published the consolidated PhantomSub analysis of 101 packages (about 490,000 downloads, 116,000 in the last 30 days). The Hacker News covered it the same day.

Sources cited for PhantomSub: 101 Malicious npm Baileys Forks Force

More in supply chain

Detection coverage for TL-2026-2785

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2785 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats