Evidence · DiggingBeagle record
PhantomRaven: NPM Malware Hidden in Invisible Dependencies
Koi Security's original PhantomRaven disclosure. It reports that the campaign began in August 2025, identified 126 malicious npm packages with more than 86,000 downloads, and describes Remote Dynamic Dependencies and slopsquatting as central delivery and lure mechanisms.
- Published
- Oct 29, 2025
- Accessed
- Sep 21, 2026
- Publisher
- Koi Security
Evidence record
Koi Security's original PhantomRaven disclosure. It reports that the campaign began in August 2025, identified 126 malicious npm packages with more than 86,000 downloads, and describes Remote Dynamic Dependencies and slopsquatting as central delivery and lure mechanisms.
Claim-level citations (2)
- supportsPhantomRaven used npm packages to deliver an information stealer likely developed with an LLM: The initial public disclosure identified 126 malicious npm packages with more than 86,000 downloads; Sonatype then reported 83 additional packages, bringing the known package count above 200. These figures measure package/download scale, not confirmed victims.
Intro and The Discovery sections reporting 126 packages and 86,000+ downloads
- supportsPhantomRaven used npm packages to deliver an information stealer likely developed with an LLM: Koi Security traced the PhantomRaven npm campaign to August 2025, earlier than the November 2025 incidents later described by CrowdStrike.
The Discovery / Timeline: campaign begins in August 2025