Bleepingcomputer
PhantomRaven Malware Campaign Targets npm Packages
First seen 2 Dec 2025, 18:33 UTC
•



+3
•26.4
Export
Article Content
Browse articles
A malware campaign named PhantomRaven has been active since August 2025, compromising 126 npm packages and stealing developer credentials, including npm tokens and GitHub credentials. Researchers at Koi Security reported that over 86,000 downloads of these infected packages occurred, with many packages appearing safe to users initially, making detection difficult.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
TA416 Resumes Cyber Espionage Against European Governments Amid Geopolitical Tensions
Multiple Critical Windows Vulnerabilities Discovered and Exploited
Chinese Hackers Exploit Windows Zero-Day to Target European Diplomats
Chinese Hackers Exploit Windows Zero-Day to Target European Diplomats
APT36's Ongoing Espionage Campaign Against Indian Government
China-linked Hackers Target U.S. Non-Profit in Espionage Campaign