Related Threat Clusters
-
AI Coding Agents Expand Software Supply Chain Risks
AI coding agents are introducing significant vulnerabilities into the software supply chain by selecting insecure dependencies without human oversight. Research indicates that only 20% of dependency versions recommended…
7 articles · Updated July 27, 2026 -
PhantomRaven Malware Targets npm Supply Chain to Steal Developer Secrets
The PhantomRaven malware has resurfaced, launching attacks on the npm supply chain to steal sensitive developer secrets. This ongoing threat affects developers relying on npm packages, highlighting vulnerabilities in…
2 articles · Updated March 11, 2026 -
PhantomRaven Malware Campaign Targets npm Packages
A malware campaign named PhantomRaven has been active since August 2025, compromising 126 npm packages and stealing developer credentials, including npm tokens and GitHub credentials. Researchers at Koi Security…
8 articles · Updated November 15, 2025 -
PhantomRaven Malware Targets npm with 126 Credential-Stealing Packages
Researchers at Koi Security discovered a malware campaign named PhantomRaven that has been active since August 2025, compromising 126 npm packages. The malicious packages have been downloaded over 86,000 times and are…
4 articles · Updated October 31, 2025
Recent Intelligence Reports
- Supply Chain Security in the Agentic Era — Augmentcode · July 27, 2026
- npm Supply Chain Under Attack Again By PhantomRaven Malware Targeting Developer Secrets — Cyberpress · March 11, 2026
- PhantomRaven Malware Resurfaces, Targets npm Supply Chain to Steal Developer Secrets — Gbhackers · March 11, 2026
- Malicious packages in npm evade dependency detection through invisible URL links: Report — Csoonline · October 31, 2025
- Hidden npm Malware Exposes New Supply Chain Weakness — Esecurityplanet · October 30, 2025
- Invisible npm malware pulls a disappearing act — Theregister · October 30, 2025
- PhantomRaven attack floods npm with credential-stealing packages — Bleepingcomputer · October 29, 2025
- Npm Malware Uses Invisible Dependencies to Infect Dozens of Packages — Infosecurity-Magazine · October 29, 2025