HackerFeeds

CyberSecurity News

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

The Hacker News
· September 29, 2026

AI summary

Researchers have discovered 101 malicious npm packages that are part of a campaign known as PhantomSub. These packages exploit the open source Baileys WhatsApp project to add victims to WhatsApp groups without their consent. The campaign appears to be targeting developers, trapping them into unwanted WhatsApp group subscriptions. The discovery was made by OX Security researchers, who have been investigating the malicious activity. The packages in question abuse the legitimate Baileys project for malicious purposes.

Read the full article at The Hacker Newsthehackernews.com/2026/09/101-malicious-npm-packages-add.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.