PhantomRaven Malware Resurfaces, Targets npm Supply Chain to Steal Developer Secrets
ID: 35683b3f-4aa3-549f-8f3e-a6b830d44af7
STIX ID: report--35683b3f-4aa3-549f-8f3e-a6b830d44af7
Feed Name: GBHackers
Threat Score
PhantomRaven is an active, large-scale npm supply-chain campaign that embeds credential-stealing malware via Remote Dynamic Dependencies in seemingly legitimate packages; researchers found 88 new malicious packages across three recent waves (November 2025–February 2026), with 81 still accessible and two C2 servers operational, posing a significant risk to developer secrets, build environments, and cloud credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
