Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

101 Malicious npm Packages Auto‑Add Developers to WhatsApp Groups Without Consent

Researchers identified 101 npm packages that abuse the Baileys WhatsApp library to add developers’ accounts to groups without permission. The campaign shows how unvetted open‑source components can create privacy‑related supply‑chain risks, underscoring the need for continuous third‑party risk monitoring.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

What Happened – Researchers uncovered a supply‑chain campaign that published 101 npm packages containing code that abuses the open‑source Baileys WhatsApp library. When a developer installs any of these packages, the malicious payload silently uses the victim’s authenticated WhatsApp session to add the account to spam groups, without the user’s knowledge or consent.

Why It Matters for Trust & Control Assurance

  • Demonstrates how unchecked third‑party components can create covert privacy violations, a scenario continuous control‑assurance programs are built to detect and evidence.
  • Highlights the need for ongoing monitoring of open‑source dependencies and proof of due‑diligence for each component in the software bill of materials (SBOM).
  • Provides a concrete example of why a vendor‑risk management capability that aggregates real‑time risk signals is essential for audit‑ready evidence.

Who Is Affected – Software developers, SaaS product teams, and any organization that builds or ships code using npm packages; the impact spans technology, fintech, health‑tech, and other sectors that rely on JavaScript/Node.js ecosystems.

Recommended Actions

  • Inventory all npm dependencies and cross‑reference them against a trusted SBOM.
  • Enable automated scanning for known malicious package signatures and for anomalous behavior (e.g., unexpected network calls to WhatsApp APIs).
  • Enforce a policy that requires security review and approval before any new third‑party library is added to production code.
  • Rotate WhatsApp authentication tokens for any accounts that may have been compromised and monitor for unsolicited group invitations.

Source: The Hacker News

Technical Notes

  • Attack vector: Malicious npm packages (third‑party dependency compromise).
  • Affected component: Baileys – an open‑source WhatsApp client library for Node.js.
  • Impact: Unauthorized addition of WhatsApp accounts to groups, leading to potential spam, phishing, or social‑engineering exposure.
  • Mitigation: Remove the malicious packages, audit code for Baileys usage, and apply strict dependency‑approval workflows.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →