logo

PhantomRaven Malware Resurfaces, Targets npm Supply Chain to Steal Developer Secrets

ID: 35683b3f-4aa3-549f-8f3e-a6b830d44af7

STIX ID: report--35683b3f-4aa3-549f-8f3e-a6b830d44af7

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-03-11

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

PhantomRaven is an active, large-scale npm supply-chain campaign that embeds credential-stealing malware via Remote Dynamic Dependencies in seemingly legitimate packages; researchers found 88 new malicious packages across three recent waves (November 2025–February 2026), with 81 still accessible and two C2 servers operational, posing a significant risk to developer secrets, build environments, and cloud credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.