Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-03 · updated: 2026-10-03 · tags: [incident, global, supply-chain] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: false

The supply-chain watch this window verified a cluster of malicious open-source packages. On 2 October, security vendor OX Security and community reviewers confirmed a "PhantomSub" family of near-identical npm forks of the Baileys WhatsApp Web library — packages such as @celestial-community/baileys, danz-bails, prastzy and xcvrenzcompany — whose publisher injects code that, without installation, can conduct covert channel-subscription activity inside a WhatsApp session, exhibiting infostealer, code-execution, obfuscation, persistence and install-script behaviour, with OSV advisory MAL-2026-17438 among those published. The same window carried a full-featured C2 RAT in use disguised as a text-beautifier (beautifytext, PyPI) and two exfiltration-capable dotenv-type npm packages (dotenv-async, promises-dotenv3). Organisations should audit dependency graphs against the affected names and versions; these are confirmed malicious assets, not raw signals.

Attribute Detail
Sector Global (Macro)
Date 2026-10-03
Source OpenSourceMalware — @celestial-community/baileys
Reliability Tier 2