PhantomSub Campaign:Malicious npm Packages Silently Hijack WhatsApp Accounts
Security researchers at OX Security, SafeDep, and Xygeni have uncovered a widespread supply-chain campaign dubbed PhantomSub. Attackers published at least 101 malicious software packages to the official npm registry—downloaded nearly 500,000 times. These packages trick developers into connecting their personal or business WhatsApp accounts (usually to build automated chatbots) and then secretly force those accounts to join WhatsApp channels, enter group chats, and broadcast unauthorized marketing links without the owner's knowledge or consent. Clear Explanation: How the Attack Works Developers often build WhatsApp automation tools or chatbots using an open-source library named Baileys. Attackers created deceptive copies (typosquatting and forks) of this original library, such as @nexustechpro/baileys or ourin-baileys. When a developer installs one of these malicious packages and scans the QR code to authenticate their WhatsApp session, the package acts normally on the surface. Howe...