Drooid Logo
Back to today’s briefing

Story perspectives

Malicious NPM Packages Exploit PhantomRaven Vulnerability, 86K Downloads

10/30/2025

31 5

1 of 1

Story summary
  • Security firm Koi says attackers exploited a vulnerability in the Node Package Manager (NPM) code repository via the PhantomRaven campaign, using NPM's Remote Dynamic Dependencies to fetch unvetted code that is automatically installed with each package.
  • Koi identified 126 malicious packages linked to PhantomRaven, downloaded over 86,000 times, with 80 still available.
  • The method bypasses security because dependencies are invisible to developers and security scanners.