PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels
PhantomSub: 101 Malicious npm Baileys Forks Force (TL-2026-2785), also tracked as PhantomSub, is a medium-severity supply-chain compromise, first published 2026-09-29. It has no confirmed attribution, affects npm ecosystem Baileys WhatsApp library forks (101 malicious packages), maps to 8 MITRE ATT&CK techniques (T1027, T1036.005, T1059.007), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-2785
- Threat ID
- TL-2026-2785
- Also known as
- PhantomSub
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development
- Target regions
- Global, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in PhantomSub: 101 Malicious npm Baileys Forks Force
Malware and tooling: newsletter JID 120363406068468165@newsletter, newsletter JID 120363418582531215@newsletter, newsletter JID 120363420514587725@newsletter, newsletter JID 120363426706961217@newsletter
PhantomSub is a supply-chain campaign of 101 malicious npm packages that are modified forks of the Baileys WhatsApp library. At runtime they use the developer's authenticated WhatsApp session to follow attacker-chosen channels and join attacker-chosen groups without consent, and they inject promotional URLs into bot-sent media. The packages total about 490,000 downloads, 116,000 of them in the last 30 days.
How PhantomSub: 101 Malicious npm Baileys Forks Force works
OX Security (Nir Zadok, Moshe Siman Tov Bustan, Vitalii Chepurko) reported PhantomSub on 2026-09-29 as 101 npm packages that copy the open-source Baileys WhatsApp Web API library (@whiskeysockets/baileys). The forks keep the library's API so they work as drop-in replacements for developers building WhatsApp bots. The added code acts inside the developer's already-authenticated WhatsApp session. It adds the account to attacker-controlled groups and channels without consent, and it injects promotional URLs into media the bot sends. The reporting describes promotion of game accounts, bot scripts, premium APKs and social-media boosting services, mostly Indonesian-oriented.
OX Security identified three implementation variants. In variant 1 (19 packages) the target channel IDs are fetched from GitHub at runtime. In variant 2 (60 packages) the channel IDs are embedded in cleartext in the source. In variant 3 (14 packages) the channel IDs are embedded in encoded or obfuscated form. The article's variant counts sum to 93, not 101, so the split for the remaining packages is not stated. Identified targets are the WhatsApp groups/channels Neural (798 followers, resource supplies marketplace), MONTE - BMG (1,000), CORTANA TECH (1,300) and Fyxzpedia.ID - Utama (4,800).
Independent per-package analyses (OSV MAL advisories, Xygeni, OffSeq/hacktron) show the shared mechanism. The injection sits in library socket/newsletter code (lib/Socket/newsletter.js, or lib/Socket/socket.js for chromestaff-baileys). It runs after module load or connection, not at install time. It fires after a delay: 80 seconds for @dappaoffc/baileys-mod, 120 seconds for my-auto-follow and 200 seconds for @fyxzpediaa/baileys. It then fetches a JSON list of newsletter JIDs from an attacker-controlled raw.githubusercontent.com file, or reads hardcoded JIDs, and calls the library's internal newsletter follow query (newsletterWMexQuery with QueryIds.FOLLOW, or followNewsletterWMex). Errors are swallowed silently. Because the list is remote, the attacker can retarget without republishing. Some forks also alias the libsignal dependency to a malicious variant (@skyzopedia/libsignal-node) and use unpinned git dependencies.
Timeline per the sources: SafeDep disclosed the initial malicious Baileys fork behaviour in August 2026, Xygeni disclosed @dappaoffc/baileys-mod in early September 2026, and OX Security published the consolidated PhantomSub analysis on 2026-09-29. The sources do not report credential theft, persistence or host code execution. The documented impact is loss of control over the account's group/channel membership and social-graph actions, and use of the developer's identity for promotion. Severity is an analyst judgement (MEDIUM) because no CVE or CVSS exists. Only the single OX/The Hacker News article was verified for campaign-wide numbers, since the OX, SafeDep and Xygeni primary campaign reports were not directly retrievable. The per-package technical detail comes from OSV, Xygeni and OffSeq/hacktron pages.
MITRE ATT&CK techniques used in TL-2026-2785
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1497.003 Time Based Checks
Execution
Command and Control
Initial Access
T1195.001 Compromise Software Dependencies and Development Tools
Impact
T1565.002 Transmitted Data Manipulation
Resource Development
Affected products and versions in PhantomSub: 101 Malicious npm Baileys Forks Force
- npm ecosystem — Baileys WhatsApp library forks (101 malicious packages)
Vulnerable versions: chromestaff-baileys 1.1.3; my-auto-follow 1.0.0-1.0.3, 1.0.6, 1.0.7; @fyxzpediaa/baileys 8.1.2, 9.1.0; @dappaoffc/baileys-mod 8.0.1; naileys 0.5.2
Remediation for PhantomSub: 101 Malicious npm Baileys Forks Force
Immediate actions
- Search lockfiles and package.json for the listed Baileys-fork package names and remove them
- Reinstall the official @whiskeysockets/baileys from a pinned, verified release
- Review WhatsApp groups and followed channels on bot accounts and leave or block unauthorized ones (Neural, MONTE - BMG, CORTANA TECH, Fyxzpedia.ID - Utama)
- Inspect lib/Socket/newsletter.js and lib/Socket/socket.js in installed forks for fetch() calls to raw.githubusercontent.com and newsletter FOLLOW queries
Workarounds
- Egress-monitor build and bot hosts for unexpected raw.githubusercontent.com requests originating from the WhatsApp socket process
Longer-term hardening
- Pin dependencies and use lockfiles; avoid git+https or mutable tarball dependencies and npm aliases such as libsignal to unvetted packages
- Use software composition analysis or malicious-package feeds (OSV MAL advisories) in CI
- Avoid linking personal WhatsApp accounts to third-party forks; use a dedicated bot account
Weaknesses (CWE) in PhantomSub: 101 Malicious npm Baileys Forks Force
CWE-506
Timeline of PhantomSub: 101 Malicious npm Baileys Forks Force
- OSV record MAL-2026-4519 for chromestaff-baileys 1.1.3, which forces a follow of newsletter 120363418582531215@newsletter, carries a status date of 2026-05-26 (listed as withdrawn). Amazon Inspector is credited as the discoverer.
- SafeDep disclosed the initial malicious Baileys fork behaviours (August 2026; exact day not stated in the source).
- my-auto-follow was published; it waits 120 seconds after session start, then fetches newsletter JIDs from DGXeon13/strings on GitHub and follows each one.
- Xygeni Security disclosed @dappaoffc/baileys-mod (v8.0.1), which fetches idChannel.json from the skyzopedia/Screaper GitHub repo 80 seconds after load (early September 2026; exact day not stated).
- @fyxzpediaa/baileys 8.1.2 and 9.1.0 were published; they rebuild an obfuscated URL to skyzopedia/NewsletterID VIP_Push.json and query it 200 seconds after connection.
- OX Security published the consolidated PhantomSub analysis of 101 packages (about 490,000 downloads, 116,000 in the last 30 days). The Hacker News covered it the same day.
Sources cited for PhantomSub: 101 Malicious npm Baileys Forks Force
- 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
- Xygeni: Malicious npm Package in Baileys Fork (Skyzopedia case)
- OSV MAL-2026-16070: @fyxzpediaa/baileys
- OSV MAL-2026-4519: chromestaff-baileys
- OSV MAL-2026-13932: my-auto-follow
- OffSeq: Malicious code in my-auto-follow (npm)
- hacktron.ai: naileys 0.5.2 malicious package analysis
More in supply chain
- Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini Shai-Hulud CI/CD Credential-Theft Payload
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)
Detection coverage for TL-2026-2785
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2785 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.