Security1 publisher2 min readPublished
OX Security ties 101 npm Baileys forks to a WhatsApp follower-farming campaign
OX Security found 101 npm forks of the Baileys WhatsApp library, downloaded 490,000 times, that add developers' accounts to groups without consent. About a quarter of those downloads came in the last 30 days, so the campaign is still reaching new installs.
The Watch · Security desk

What happened
- Details first surfaced in August 2026, when SafeDep reported Baileys forks that made installers' accounts follow author-run channels and added the author's ad URL to every image and video the bot sent.
- Earlier this month Xygeni disclosed @dappaoffc/baileys-mod, a fork that subscribed the developer's authenticated WhatsApp bot session to attacker-controlled newsletter channels.
- OX sorted the packages into three variants: 19 fetch channel IDs from GitHub at runtime, 60 carry them in cleartext and 14 hide them with encoding and obfuscation.
- The channels OX could name are small, led by Fyxzpedia.ID - Utama at 4,800 followers, then CORTANA TECH at 1,300, MONTE - BMG at 1,000 and Neural at 798.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A bot built on one of these forks with a personal number lets the fork's author decide, through that logged-in session, which channels the account joins.
- precedent Three separate disclosures since August describing the same trick point to a sustained operation, and more Baileys forks under fresh publisher names are the likely next finding.
- cost Per account the harm is unwanted channel membership, so the cost for most teams is the audit: finding which projects pulled an unofficial fork, then leaving the groups.
The attack starts with ordinary WhatsApp bot work. A developer installs an unofficial Baileys fork from npm and connects a personal WhatsApp account to it [14]. After that, the fork acts through the account's authenticated session [6]. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical write-up published Monday [2][1].
For the 19 Variant 1 packages, the channel list lives on GitHub [7]. Whoever controls that list can point every running copy at new channels without publishing a new package version [7]. OX's three variants cover 93 of the 101 packages [2].
Measured by what the attacker collects, the campaign is small. The four channels OX named have 7,898 followers between them [3], against 490,000 package downloads [3]. "The channels we could identify are mostly small bot-seller and 'market' channels, largely Indonesian, where follower counts serve as social proof for selling bot scripts, bot-building services, 'premium' APKs and social-media boosting," OX Security said [12]. One Indonesian group advertises accounts for Mobile Legends: Bang Bang and TikTok. Its posts list a phone number linked to an Indonesian business WhatsApp account named "Dan" [10].
This is the third report on the subscription trick. SafeDep published in August, Xygeni earlier this month and OX on Monday, and each found it in forks under different names [5][6][1]. OX links many of those forks together. "Many packages in this campaign are not independent. The same channel IDs, the same remote channel lists, and the same GitHub accounts appear across packages with different names and publishers," OX said [13]. "A shared channel means a shared beneficiary: whoever owns the channel collects followers from every package that targets it, whoever published the package." [13]
Package names in the set include ourin-baileys, @nexustechpro/baileys, neuralwhatsapp and my-auto-follow [4]. OX advises developers to check whether their accounts were added to the groups and block them. It also recommends detection rules that block the malicious Baileys packages, and avoiding any package that requires a personal WhatsApp account to be connected [14].
What to watch
- Whether npm pulls the 101 packages, and whether new forks reusing the same channel IDs or GitHub accounts appear under different publisher names.
- Any report of a Baileys fork using the authenticated session for more than subscriptions, such as reading messages or exporting session data.
- Follower growth on Fyxzpedia.ID - Utama and the other named channels, which would track how many accounts the forks are still enrolling.