VDB
GCVE-110-OSM-2026-12773
GCVE-110-OSM-2026-12773
Advisory PublishedCVSS 5.4/10
This package is a fork of the Baileys WhatsApp library that quietly makes the installer's WhatsApp account follow and mute channels controlled by the package author, without consent. It is part of the PhantomSub campaign, which inflates follower counts for channels that sell accounts, bot scripts and similar goods. It does not steal credentials or crypto, but it modifies the victim's account and exposes them to scam content. It has been removed from npm.
## Payload 1: WhatsApp channel auto-follow
Malicious payload found in: unknown (not stated in source)
- Trigger: code inside the bundled Baileys fork, active while the package is connected to a WhatsApp account.
- Behavior: calls the newsletter follow and mute functions for each channel ID it holds, using the connected account.
- Removed from npm before its code could be reviewed, so the variant used is unknown.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | anuaja | all (affected) | — |
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.