101 Malicious npm Packages Add Developers’ WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub.

« The malicious packages abuse the ‘Baileys’ WhatsApp open source project to add the victims to groups without their consent, » OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical