The supply-chain watch this window verified a cluster of malicious open-source packages. On 2 October, security vendor OX Security and community reviewers confirmed a "PhantomSub" family of near-identical npm forks of the Baileys WhatsApp Web library — packages such as @celestial-community/baileys, danz-bails, prastzy and xcvrenzcompany — whose publisher injects code that, without installation, can conduct covert channel-subscription activity inside a WhatsApp session, exhibiting infostealer, code-execution, obfuscation, persistence and install-script behaviour, with OSV advisory MAL-2026-17438 among those published. The same window carried a full-featured C2 RAT in use disguised as a text-beautifier (beautifytext, PyPI) and two exfiltration-capable dotenv-type npm packages (dotenv-async, promises-dotenv3). Organisations should audit dependency graphs against the affected names and versions; these are confirmed malicious assets, not raw signals.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-03 |
| Source | OpenSourceMalware — @celestial-community/baileys |
| Reliability | Tier 2 |