CyberSecurity News
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
AI summary
Researchers have discovered 101 malicious npm packages that are part of a campaign known as PhantomSub. These packages exploit the open source Baileys WhatsApp project to add victims to WhatsApp groups without their consent. The campaign appears to be targeting developers, trapping them into unwanted WhatsApp group subscriptions. The discovery was made by OX Security researchers, who have been investigating the malicious activity. The packages in question abuse the legitimate Baileys project for malicious purposes.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

