101 Poisoned Grain Bags Found in the Developer Trough. Surprise, You're in a Group Chat Now.
Oh good. A Monday.
So researchers over at OX Security found 101 malicious npm packages, all quietly doing the digital equivalent of signing you up for a timeshare newsletter. Except instead of a newsletter, it's a WhatsApp group. And instead of you consenting to any of it, the parasites just... did it. While you were trying to do your job.
The campaign is called PhantomSub, which honestly sounds like a submarine thriller I'd watch at 3am because I can't sleep due to alert fatigue. But no. It's just wolves abusing the Baileys WhatsApp open source library to silently add developers to groups without their knowledge or permission.
101 packages. One hundred and one. Someone sat down, made a coffee, and spent their morning crafting over a hundred fake grain bags and dropping them in the npm trough. And developers, bless their little hooves, just ate from it.
I want to be sympathetic. I really do. But these are developers. People who are supposed to know better. The Lambs clicking fake grain in a phishing email, fine, they don't know any better, that's why we have the Electric Fence. But you, with your IDE open and your terminal running, you pulled an unverified package and now you're in a group chat called "CRYPTO PROFITS 🚀" with 400 strangers.
I need to lie down.
The actual threat here is worth paying attention to for two seconds before I go back to ignoring my ticket queue. Package-based supply chain attacks are getting lazier and more brazen at the same time. The fleas don't even need to steal your credentials anymore. They just need to establish presence, prove they can execute code in your environment, and then wait. Today it's a WhatsApp group. Tomorrow it's something that actually ruins your week.
The Shepherds will read this headline, nod gravely, and ask if it affects the quarterly roadmap. It does not affect the quarterly roadmap. Nothing ever affects the quarterly roadmap.
Remediation
Look, I'm tired, so I'll keep this short.
- Audit your npm dependencies. Yes, all of them. Yes, right now. No, "later" is not an answer.
- Check for unexpected Baileys or WhatsApp-related libraries in projects that have absolutely no business touching WhatsApp.
- Use a software composition analysis tool that actually flags suspicious packages before they land in your build pipeline, not after you're already in the group chat.
- Lock your dependency versions and verify checksums. Treat the npm trough like the Sky Pasture: convenient, suspicious, and absolutely not to be trusted blindly.
Going back to my cold coffee and my 47 unread tickets now.
Original Report: https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html