Bleepingcomputer
PhantomRaven Malware Campaign Targets npm Packages
First seen 2 Dec 2025, 18:33 UTC
•



+3
•77% similarity
•26.4
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A malware campaign named PhantomRaven has been active since August 2025, compromising 126 npm packages and stealing developer credentials, including npm tokens and GitHub credentials. Researchers at Koi Security reported that over 86,000 downloads of these infected packages occurred, with many packages appearing safe to users initially, making detection difficult.
ThreatCluster AI
How this analysis works