logo

New PhantomRaven NPM attack wave steals dev data via 88 packages

ID: 50059303-090b-50b3-9634-0eff53a1492f

STIX ID: report--50059303-090b-50b3-9634-0eff53a1492f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-11

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

Researchers observed the PhantomRaven supply‑chain campaign publishing dozens of malicious npm packages (88 in recent waves, 126 earlier) that abuse 'Remote Dynamic Dependencies' to download and run payloads which harvest developer information (emails, .npmrc/.gitconfig, environment variables, CI/CD tokens), fingerprint hosts, and exfiltrate data to C2 endpoints; the infrastructure and payloads remained largely consistent across waves while attackers rotated accounts, domains, and endpoints, and many malicious packages remain available in the npm registry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.