chiprook
← Security
SecuritySeptember 29, 2026, 20:45

101 Malicious npm Packages Add Developers to WhatsApp Groups Without Consent

Researchers at OX Security uncovered 101 npm packages in a campaign dubbed PhantomSub that abuse the open-source Baileys WhatsApp project to add developers to groups without their consent.

101 Malicious npm Packages Add Developers to WhatsApp Groups Without Consent
#Npm#WhatsApp#Baileys
Read next
Security

Malicious npm Package Poses as Twilio Security Tool, Steals Credentials

Security

Malicious npm packages evade install-script defenses at runtime

Security

Malicious npm Package Found in Job Take-Home Test

Security

Compromised MemTensor packages push sckit credential stealer via npm and PyPI