logo

PhantomRaven attack floods npm with credential-stealing packages

ID: d7c0f88e-571e-54f1-8c9c-a2af0fd5287c

STIX ID: report--d7c0f88e-571e-54f1-8c9c-a2af0fd5287c

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-29

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

PhantomRaven is an active supply-chain campaign that pushed 126 malicious npm packages (more than 86,000 downloads) which declare no dependencies but fetch and execute remote payloads during 'npm install'; these payloads profile victims and steal credentials and CI/CD tokens (NPM, GitHub, GitLab, Jenkins, CircleCI) and exfiltrate data via HTTP GET/POST and WebSocket, with Koi Security publishing IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.