Downloads across the 101 packages: 490,000 (Source: OX Security (September 28, 2026))
Most malware takes something. It goes after passwords, API keys or crypto. This campaign takes none of those. It borrows the logged-in WhatsApp account of the developer who installed it. The lesson: a bad dependency can misuse an account without stealing anything. OX says the classic detection signatures are absent, so tools built around them can miss this.
What OX Security found
OX Security's research team found 101 npm packages in a campaign the reporting calls PhantomSub. The packages abuse Baileys, an open source project. Baileys gives developers an unofficial way to automate WhatsApp. Typical uses are customer support bots and chat managers.
The packages are forks, meaning modified copies, of the upstream library @whiskeysockets/baileys. Once installed, they make the developer's WhatsApp account follow channels chosen by the package author. They also mute those channels on the developer's device. OX says one package, spencer-baileys, waits 90 seconds before it follows.
OX could identify some of the channels. Most are small sellers of bot scripts, premium APKs and social media boosting. OX describes them as largely Indonesian. One advertises TikTok and mobile game accounts.
Each new follower raises a channel's count. That count works as social proof. In OX's example, a buyer is drawn in by the number. The deal then moves to a private group.
How it works
The packages share one payload. They differ in how they supply the list of channels to follow.
In 19 packages, the list sits in a file on GitHub. The package fetches it while running. The operator can edit that file and retarget every installed copy. No new npm release is needed.
In 60 packages, the channel IDs are written in plain text in the code. In 14 packages, OX describes the IDs as encoded in Base64 and obfuscated. Base64 is a simple text encoding that hides content from a casual reader.
OX could not review seven other packages, because npm removed them first. It does not say which variant those used.
Some packages hid the code in large files where a reviewer could easily miss it. One added its follow-and-mute logic to the upstream library's own connection handler. Another put a copy of a newsletter module in a file named for the Signal protocol. That protocol is part of WhatsApp's encryption layer.
Why it is easy to miss
OX points to what the packages lack. It says classic malicious-code signatures are absent, such as stealing API tokens and heavy obfuscation. Most of the packages avoid heavy obfuscation, though OX describes 14 as encoded. OX says campaigns like this can slip under the radar in threat detection tools and inside large organisations. It adds that they can stay online longer than typical malware.
Removal is also hard. The same payload is republished under lookalike names. OX lists pairs such as noxleyss and @noxleyss/baileys. Taking down one leaves the other in place. As of September 28, only 16 of the 101 packages had been removed from npm.
That overlap links packages that look unrelated. One channel is followed by 10 packages. One remote list feeds five. OX reasons that whoever owns a shared channel collects followers from every package that targets it. That holds even when the packages carry different names and publishers.
What this means for an organisation
The direct target is the developer whose account is connected. OX says the campaign is not aimed at stealing data or crypto. It does expose unaware people to scams and illegal trade. The report does not say any company systems were affected.
It does show what a dependency can do once it holds a live session. It also shows the limit of install-time review. In the 19 remote-list packages, behaviour depends on a file that can change after the review. The code you approved is not the whole picture.
One caveat on who benefits. OX confirmed only three channels as auto-follow targets. Others it found are promoted by the package authors, in their READMEs or code. OX says these are most likely run by the same people who receive the followers. That is an inference, not a confirmed link.
Questions to put to your team
Do any of our bots, tools or scripts use Baileys or a fork of it? Do our lockfiles list packages from the OX report? Do they show forks other than the upstream @whiskeysockets/baileys?
Does any package ask developers to connect a personal account? OX advises against using such packages. Can we block or alert on the flagged packages when they are added as dependencies?
OX also recommends adding the remote list URLs, channel IDs and invite codes from its report to threat-intelligence and URL-reputation feeds. Developers added to unfamiliar groups should report and block them. They should not engage with the sellers.
A package does not need to steal from you to be worth removing. If it acts through an account you did not agree to share, it belongs on the same list.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: OX Security.





