On September 28, 2026, OX Security reported that it had identified 101 npm packages associated with PhantomSub, a campaign that allegedly abused Baileys to add authenticated WhatsApp accounts to groups or channels without consent. Baileys is an unofficial implementation of the WhatsApp API that developers can use to automate account actions.
What OX Security reported about PhantomSub
OX Security said the packages used Baileys to make accounts join groups or follow channels without their owners’ consent. The company reported about 490,000 cumulative downloads across the packages, including 116,000 during the 30 days before its September 28 report.
OX Security said 16 packages had been removed from npm as of September 28, 2026.
Three reported ways to handle channel IDs
OX Security described three approaches the packages used to obtain or store channel IDs. Some fetched IDs from GitHub when they ran; others embedded IDs directly in the package code, either in cleartext or in encoded or obfuscated form.
| Reported approach | Where the channel IDs come from | How they are handled |
| Runtime retrieval | GitHub | The package fetches the IDs when it runs. |
| Cleartext embedding | The package itself | The IDs appear directly in the code. |
| Encoded or obfuscated embedding | The package itself | The IDs are stored in encoded or disguised form. |
Why the packages targeted channels
OX Security assessed that the campaign aimed to inflate channel audiences and make sellers look more credible to potential customers. The channels it identified were mostly small and largely Indonesian, promoting activities such as selling bot scripts, bot-building services, premium APKs, and social-media boosting.
OX Security characterized the campaign as follower inflation, not a direct effort to steal data or cryptocurrency.
What developers can do
OX Security recommended checking WhatsApp accounts for unwanted group additions, then blocking and reporting suspicious groups. For development environments, it advised adding detection rules for the malicious packages and avoiding dependencies that require a personal WhatsApp account.