Story perspectives
Malicious NPM Packages Exploit PhantomRaven Vulnerability, 86K Downloads
10/30/2025
31 5
1 of 1
Story summary
- Security firm Koi says attackers exploited a vulnerability in the Node Package Manager (NPM) code repository via the PhantomRaven campaign, using NPM's Remote Dynamic Dependencies to fetch unvetted code that is automatically installed with each package.
- Koi identified 126 malicious packages linked to PhantomRaven, downloaded over 86,000 times, with 80 still available.
- The method bypasses security because dependencies are invisible to developers and security scanners.
