Home / Mar 12, 2026 / Story
0
#5 BleepingComputer general March 11, 2026 at 17:09 UTC

New PhantomRaven NPM attack wave steals dev data via 88 packages

By Bill Toulas

AI Summary

The PhantomRaven supply-chain campaign launched new attacks on npm registry with 88 malicious packages designed to exfiltrate sensitive data from JavaScript developers. These packages masquerade as legitimate development tools while stealing credentials and project data from compromised developer environments.

Relevance score: 85.0/100

# More from March 12