PhantomRaven Malware Campaign Targets npm Packages

PhantomRaven Malware Campaign Targets npm Packages

First seen 2 Dec 2025, 18:33 UTC Infosecurity-MagazineBleepingcomputerTheregisterEsecurityplanetCsoonline+3 77% similarity 26.4

Article Content

Browse articles
ThreatCluster

A malware campaign named PhantomRaven has been active since August 2025, compromising 126 npm packages and stealing developer credentials, including npm tokens and GitHub credentials. Researchers at Koi Security reported that over 86,000 downloads of these infected packages occurred, with many packages appearing safe to users initially, making detection difficult.

ThreatCluster AI How this analysis works

Community

Browse all →