I read The Hacker News on September 29, 2026. The research note they cite is from OX Security. Three people signed it. I am keeping the surnames: Zadok, Bustan, and Chepurko.
The count is 101 packages on npm. They call the campaign PhantomSub. It uses Baileys, the open-source WhatsApp code, and the claim is that a developer's account gets dropped into groups the person did not ask to join.
I am not walking through the package code. If a laptop is logged into WhatsApp and also installs from npm, this is the report I would open before I shrug.
Source I used: The Hacker News. The link is under this column.