Supply Chain Attack

关注

Malicious packages overwhelm NPM with over 86,000 downloads

Theo Klein

Security firm Koi has uncovered a campaign called PhantomRaven that flooded the NPM registry with 126 malicious packages since August. These packages, downloaded more than 86,000 times, exploit a feature allowing unvetted dependencies from untrusted sites. As of late October 2025, about 80 of the packages remained available.

本网站使用 Cookie

我们使用 Cookie 进行分析以改善我们的网站。 阅读我们的 隐私政策 以获取更多信息。
拒绝