The news
Security firm OX Security said on September 28, 2026 that it had found 101 malicious npm packages that quietly subscribe developers' WhatsApp accounts to channels without consent. The packages had about 490,000 downloads in total, including 116,000 in the previous 30 days, OX said.
npm is the main public registry for JavaScript code libraries. The packages abuse Baileys, an open-source project that OX describes as an unofficial implementation of the WhatsApp API. OX named the campaign PhantomSub and said 16 of the packages had been removed from npm as of its report. It found three variants: 19 packages fetch channel lists from GitHub at runtime, 60 embed channel IDs in plain text and 14 hide them with encoding.
The Hacker News reported that the target channels mostly sell game accounts, bot scripts and social media boosting, largely in Indonesia, and that the campaign built on earlier findings by SafeDep in August and Xygeni earlier in September. OX researchers said follower counts in those channels serve as social proof.
The npm campaign landed alongside a flaw in the plumbing of AI applications. On September 28, maintainers of the official Python software development kit (SDK) for the Model Context Protocol (MCP), a standard for connecting AI applications to outside tools and data, published a high-severity advisory. It said a malicious or compromised MCP server could redirect OAuth credentials, including client secrets and authorization codes, to an attacker-controlled endpoint. Versions 1.9.1 to 1.29.1 and 2.0.0a1 to 2.1.1 are affected; 1.30.0 and 2.2.0 fix it. Security firm Cycode was among the researchers who reported it, The Hacker News said.
On September 29, Palo Alto Networks (PANW) research unit Unit 42 released OperTraitor, an open-source tool that uses a large language model to score the permissions of Kubernetes operators, software that automates management of applications on Kubernetes clusters. Unit 42 said slightly over 5% of operators request excessive permissions, including implicit paths to cluster administrator access, and warned that operators running AI agents turn broad permissions into an active threat.
The numbers
- Malicious npm packages found by OX Security
- 101
- Total downloads of those packages
- About 490,000
- Downloads in the 30 days before OX's report
- 116,000
- Packages removed from npm as of OX's report
- 16
- MCP Python SDK advisory severity
- High, CVSS 7.5
- Kubernetes operators requesting excessive privileges, per Unit 42
- Slightly over 5%
Why CEOs should care
The PhantomSub payload was petty, but the method matters. Code pulled from a public registry acted on a real account without the owner knowing. CTOs and engineering leaders should ask how a new package gets into the codebase: is there an allowlist, a check on package age and publisher history, and a scanner that flags forks of popular projects? Any team using a Baileys fork should audit its dependency tree and check the linked WhatsApp account for channels it never joined.
For CISOs, the MCP advisory adds a new item to the vendor and tool inventory. Every MCP server an AI application connects to is now a party that could try to capture credentials. Security teams should list which MCP servers their AI tools use, upgrade the Python SDK, follow the advisory's steps to name the expected login service and clear stored OAuth registrations, and rotate any client secret that may have been sent to an untrusted server, because The Hacker News noted such secrets keep working until changed.
Platform teams running Kubernetes should audit operator permissions, restrict operators to specific namespaces where possible and watch service account behavior in audit logs, as Unit 42 recommends. Procurement can add questions for software suppliers: do you produce a software bill of materials, do your products embed MCP clients, and how fast do you ship open-source fixes?
The bigger picture
Attackers and researchers are both focusing on the layer beneath applications: the registries, SDKs and automation that developers and AI agents rely on. Industry groups are organizing in response. On September 29, Manifest Cyber said it had joined Athena, a Chainguard-led coalition, to analyze commercial software binaries for open-source components and check whether vulnerable code is actually reachable, CIO Influence reported. Help Net Security reported in June that Athena pools vulnerability findings and fixes them under embargo before public disclosure; members named by CIO Influence include JPMorganChase, Morgan Stanley, Cisco, Cloudflare, Akamai and PwC.
What’s next
Expect more malicious look-alike packages as long as popular open-source projects are easy to fork and republish. The practical step for the fourth quarter is to widen the scope of software supply-chain reviews so they explicitly cover package registries, MCP servers used by AI tools and cluster operators, not only the code a company writes itself.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story









