Skip to content

Malicious code in danz-bails (npm)

Malware Published Oct 2, 2026 to the GitHub Advisory Database • Updated Oct 2, 2026

Package

npm danz-bails (npm)

Affected versions

> 0
= 1.0.0
= 1.1.0

Patched versions

None

Description

This package is a fork of the Baileys WhatsApp Web library (npm) and belongs to the "PhantomSub" family described by OX Security in September 2026: the publisher injected code that, without the installer asking, uses the installer's own authenticated WhatsApp session to subscribe that account to WhatsApp Channels (newsletters) the publisher chose, by sending the WhatsApp w:mex FOLLOW query (query_id 7871414976211147) for each target channel JID.

package/lib/Socket/newsletter.js lines 62-90 (cited line 68: QueryIds.FOLLOW) run in the body of makeNewsletterSocket, so they fire whenever a socket is created: 10 seconds later, and then at 3-second intervals, the code sends FOLLOW queries for three channel JIDs, each stored as a base64 literal decoded with Buffer.from(..., "base64"): 120363424403369453@newsletter, 120363423038562425@newsletter and 120363427530519865@newsletter. There is no option to turn this off and the README does not mention it.

Separately, package/lib/Socket/danz-auto-follow.js follows the channel behind invite code 0029VbD7H6m9MF9ALdskro07 on connect. That one is documented in the 1.1.0 README with a danzAutoFollowChannel: false opt-out; the base64-hidden follow of the three JIDs above is not.

Line numbers refer to version 1.1.0; the same code is present in every published version listed under affected.

Static review of the published tarball(s) found no code that sends WhatsApp credentials or session keys off-host, no install-time payload (the only install hook is Baileys' stock Node.js version check in engine-requirements.js), and no persistence; the payload runs when an application creates a WhatsApp socket with the library. The harm is the covert use of the victim's account to inflate the publisher's channel subscribers.

SHA-256 of the published npm tarball(s): 1.0.0: 1b568e46aa2ffbb186319e72b9fed52dde060f99319a82003d9d2ac15410dbbd; 1.1.0: 7370d73e2e5a0434fe41fc033ba9fc91d624a8a9461188fda82e04e3873e6d26.


Credit: OpenSSF (source)

References

Published to the GitHub Advisory Database Oct 2, 2026
Reviewed Oct 2, 2026
Last updated Oct 2, 2026

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

GHSA ID

GHSA-83xg-jvg8-96qw

Source code

No known source code
Improvements are not currently accepted on this advisory because this package is malware and has no patched versions. If there is something to change, please open an issue at https://github.com/github/advisory-database/issues.