Security experts have discovered 101 npm packages that trick developers into joining WhatsApp groups without their permission, part of a campaign called PhantomSub. The activity was first reported in August 2026, when SafeDep identified a set of Baileys npm forks engaging in malicious behaviors, such as stealthily following the installer's WhatsApp account to channels controlled by the package author and injecting the author's advertising URL into every image and video sent by the bot.
The group advertises accounts associated with an Indonesian business WhatsApp account named "Dan." Other groups and channels that have been identified include: Neural (798 followers), which utilizes JualanRSS, an online marketplace specializing in in-game resources such as food, ore, stone, timber, and gold, is targeting the market for Resource Supplies (RSS) sales. MONTE – BMG (1,000 followers) CORTANA TECH (1,300 followers) Fyxzpedia.ID – Utama (4,800 followers) "The channels we've identified are mostly small bot-sellers and 'market' channels, primarily from Indonesia, where follower counts serve as social proof for selling bot scripts, bot-building services, 'premium' APKs, and social-media boosting tools," OX Security explained.










