Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Brian Greenberg :verified:
@brian_greenberg@infosec.exchange  ·  activity timestamp 12 hours ago

NPM just got hit by another supply chain mess. Attackers uploaded 126 credential-stealing packages that used “Remote Dynamic Dependencies” to quietly fetch malware from untrusted sites. Over 86,000 downloads later, the campaign (dubbed PhantomRaven) shows how blind traditional scanning still is to dynamic or AI-generated code patterns. What makes this dangerous isn’t just the malicious code, it’s the infrastructure gap. Dependencies downloaded “fresh” on install mean attackers can serve clean code to researchers and poison code to production networks. That’s targeted compromise at scale.

⚠️ 126 malicious NPM packages
🧠 Exploits Remote Dynamic Dependencies
🎯 Targets CI/CD environments
🔐 Invisible to static analysis tools

https://arstechnica.com/security/2025/10/npm-flooded-with-malicious-packages-downloaded-more-than-86000-times/

#SupplyChainSecurity #OpenSource #CyberSecurity #NPM #security #privacy #cloud #infosec

Ars Technica

NPM flooded with malicious packages downloaded more than 86,000 times

Packages downloaded from NPM can fetch dependancies from untrusted sites.
  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.4.1 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login