PhantomRaven npm Supply-Chain Attack: 126 Malicious Packages & Hidden Dependencies
The ongoing PhantomRaven npm supply chain attack is a sophisticated malware campaign targeting developers worldwide. Since August 2025, the campaign has distributed 126 malicious npm packages that have been downloaded more than 86,000 times. Its goal is to steal npm authentication tokens, GitHub credentials and CI/CD secrets, while employing advanced evasion techniques to bypass many … Read more