Evidence · DiggingBeagle record
PhantomRaven: npm Malware Uses Remote Dynamic Dependencies
Sonatype Security Research analysis that added 83 packages to the known PhantomRaven set, bringing the reported total above 200, and documented install-time remote dependency behavior, credential-oriented data collection, and exposure of developer, CI/CD, and container build environments.
- Published
- Oct 31, 2025
- Accessed
- Sep 21, 2026
- Publisher
- Sonatype
Evidence record
Sonatype Security Research analysis that added 83 packages to the known PhantomRaven set, bringing the reported total above 200, and documented install-time remote dependency behavior, credential-oriented data collection, and exposure of developer, CI/CD, and container build environments.
Claim-level citations (1)
- supportsPhantomRaven used npm packages to deliver an information stealer likely developed with an LLM: The initial public disclosure identified 126 malicious npm packages with more than 86,000 downloads; Sonatype then reported 83 additional packages, bringing the known package count above 200. These figures measure package/download scale, not confirmed victims.
Opening paragraphs reporting 83 additional packages and more than 200 total