PhantomRaven Malware Campaign Targets npm Packages

PhantomRaven Malware Campaign Targets npm Packages

First seen 2 Dec 2025, 18:33 UTC Infosecurity-MagazineBleepingcomputerTheregisterEsecurityplanetCsoonline+3 26.4

Article Content

Browse articles
ThreatCluster

A malware campaign named PhantomRaven has been active since August 2025, compromising 126 npm packages and stealing developer credentials, including npm tokens and GitHub credentials. Researchers at Koi Security reported that over 86,000 downloads of these infected packages occurred, with many packages appearing safe to users initially, making detection difficult.

Ask AI about this cluster