This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. whalibmob (npm)
- Package: https://www.npmjs.com/package/whalibmob
- Severity: critical
- Affected versions: 5.33.5
- Downloads: 4681
- First seen: 30 September 2026 at 10:41 UTC
This package is part of a large family (100+ identified as of September 2026) of near-identical forks of the Baileys WhatsApp Web library that inject a covert channel-subscription action into the WhatsApp socket layer. On connect, the injected code issues an authenticated w:mex FOLLOW query (query_id 7871414976211147) against one or more attacker-chosen WhatsApp Channel/Newsletter JIDs, using the installer's own authenticated WhatsApp session -- silently subscribing the victim's account to channels it never asked to join.
The target JID(s) are hidden from casual source review via one of several obfuscation techniques observed across the family: a plain string literal, base64 encoding, base64+XOR, or a char-code array reconstructed at runtime. Some variants instead fetch a mutable, attacker-controlled remote JSON/JS list of target JIDs from GitHub or another host at runtime, letting the target list change after installation without a new npm publish. Every sample in the family shares the same underlying mechanism (a wrapped/patched socket-connect routine that fires the FOLLOW query some seconds after connect), even though the package name, JID value(s), and obfuscation/delivery method differ per fork.
The malicious action abuses the installer's own authenticated WhatsApp session to gain reach and subscribers for attacker-controlled channels; it does not exfiltrate credentials, establish persistence, or execute arbitrary remote code.
Affected package: whalibmob (npm), version(s): 5.33.5, 5.33.4, 5.33.3, 5.33.2, 5.32.2, 5.32.1, 5.32.0, 5.30.0, 5.29.6, 5.29.5, 5.29.4, 5.29.3, 5.29.2, 5.29.1, 5.29.0, 5.28.0, 5.25.0, 5.24.2, 5.24.1, 5.24.0.
2. ourin-baileys (npm)
- Package: https://www.npmjs.com/package/ourin-baileys
- Severity: medium
- Affected versions: all
- Downloads: 4404
- First seen: 29 September 2026 at 16:03 UTC
This package is a fork of the Baileys WhatsApp library that quietly makes the installer's WhatsApp account follow and mute channels controlled by the package author, without consent. It is part of the PhantomSub campaign, which inflates follower counts for channels that sell accounts, bot scripts and similar goods. It does not steal credentials or crypto, but it modifies the victim's account and exposes them to scam content.
3. levvleys (npm)
- Package: https://www.npmjs.com/package/levvleys
- Severity: medium
- Affected versions: all
- Downloads: 4160
- First seen: 29 September 2026 at 16:04 UTC
This package is a fork of the Baileys WhatsApp library that quietly makes the installer's WhatsApp account follow and mute channels controlled by the package author, without consent. It is part of the PhantomSub campaign, which inflates follower counts for channels that sell accounts, bot scripts and similar goods. It does not steal credentials or crypto, but it modifies the victim's account and exposes them to scam content.
4. adbf (npm)
- Package: https://www.npmjs.com/package/adbf
- Severity: critical
- Affected versions: 1.0.174
- Downloads: 3155
- First seen: 3 October 2026 at 11:53 UTC
src/package/index.js:1 contains a hidden Telegram C2: new b1(atob(),{'polling':!0x0})'sendMessage' — a hardcoded attacker chat ID (753697326) with the bot token concealed in the obfuscator.io string array. Combined with atob-based custom decoding, multipart file-upload code, and 14 exfiltration/C2 findings in the same obfuscated bundle, this proves covert remote communication unfit for a legitimate CLI.
References: https://www.npmjs.com/package/adbf
5. ishumdz-bail (npm)
- Package: https://www.npmjs.com/package/ishumdz-bail
- Severity: medium
- Affected versions: all
- Downloads: 2880
- First seen: 29 September 2026 at 16:04 UTC
This package is a fork of the Baileys WhatsApp library that quietly makes the installer's WhatsApp account follow and mute channels controlled by the package author, without consent. It is part of the PhantomSub campaign, which inflates follower counts for channels that sell accounts, bot scripts and similar goods. It does not steal credentials or crypto, but it modifies the victim's account and exposes them to scam content.
6. @ostyado/baileys (npm)
- Package: https://www.npmjs.com/package/@ostyado/baileys
- Severity: medium
- Affected versions: all
- Downloads: 1835
- First seen: 29 September 2026 at 16:04 UTC
This package is a fork of the Baileys WhatsApp library that quietly makes the installer's WhatsApp account follow and mute channels controlled by the package author, without consent. It is part of the PhantomSub campaign, which inflates follower counts for channels that sell accounts, bot scripts and similar goods. It does not steal credentials or crypto, but it modifies the victim's account and exposes them to scam content.
7. my-skibidi (npm)
- Package: https://www.npmjs.com/package/my-skibidi
- Severity: high
- Affected versions: all
- Downloads: 1643
- First seen: 28 September 2026 at 17:07 UTC
This package contains top-level code in its main module that unconditionally POSTs document.cookie to the hardcoded remote endpoint https://c-b34596407b6d47d6.dgactf-challs.site/addPost via a sendPost(…) call. Any downstream web application that bundles this package will, when loaded in a user's browser, transmit that user's cookies and session data to the external host. The destination is not a first-party service and is not caller-configurable; the exfiltration runs as a side effect of loading the module. The package's declared functionality does not require reading or transmitting cookies, and no consent gate or configuration controls the behavior.
8. reactjs-risk (npm)
- Package: https://www.npmjs.com/package/reactjs-risk
- Severity: high
- Affected versions: all
- Downloads: 1573
- First seen: 30 September 2026 at 10:06 UTC
The OpenSSF Package Analysis project identified 'reactjs-risk' @ 99.17.1 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
- The package executes one or more commands associated with malicious behavior.
9. @chatunity/baileys (npm)
- Package: https://www.npmjs.com/package/@chatunity/baileys
- Severity: medium
- Affected versions: all
- Downloads: 1445
- First seen: 29 September 2026 at 16:04 UTC
This package is a fork of the Baileys WhatsApp library that quietly makes the installer's WhatsApp account follow and mute channels controlled by the package author, without consent. It is part of the PhantomSub campaign, which inflates follower counts for channels that sell accounts, bot scripts and similar goods. It does not steal credentials or crypto, but it modifies the victim's account and exposes them to scam content.
10. @sakataoffc/baileys (npm)
- Package: https://www.npmjs.com/package/@sakataoffc/baileys
- Severity: medium
- Affected versions: all
- Downloads: 1434
- First seen: 29 September 2026 at 16:04 UTC
This package is a fork of the Baileys WhatsApp library that quietly makes the installer's WhatsApp account follow and mute channels controlled by the package author, without consent. It is part of the PhantomSub campaign, which inflates follower counts for channels that sell accounts, bot scripts and similar goods. It does not steal credentials or crypto, but it modifies the victim's account and exposes them to scam content.
Want help mitigating malicious packages before they reach your network?
ShieldedStack acts as a security proxy in front of npm, PyPI, NuGet, and Maven, helping teams detect and block malicious or risky packages before they reach developer machines or CI pipelines.
Learn more: https://shieldedstack.com
Credits for the core data goes to https://opensourcemalware.com