Malware Campaign in NPM Registry Steals GitHub Tokens
Researchers uncovered a major supply-chain attack (codenamed “PhantomRaven”) affecting at least 126 packages in the npm registry. The malware uses remote dependencies hosted on attacker-controlled servers to bypass detection and, via pre-install hooks, harvests developer credentials including GitHub tokens and CI/CD secrets. The campaign has been active since August 2025 and has amassed over 86,000 downloads, underscoring the urgent need for auditing dependencies and rotating exposed credentials.
Comments
Post a Comment