Skip to content
Threat Note Threat Note

Aggregating Cyber Insights

  • Articles
  • Breaches
  • Learning
  • News
  • Podcast
  • Research
  • Toolkit
  • Vulnerabilities
  • Webinars
  • About Us
  • Home
  • News
  • From Dark Reading – Malicious NPM Packages Disguised With ‘Invisible’ Dependencies
From Dark Reading – Malicious NPM Packages Disguised With ‘Invisible’ Dependencies
Posted inNews

From Dark Reading – Malicious NPM Packages Disguised With ‘Invisible’ Dependencies

Posted by Samir K October 30, 2025

In the “PhantomRaven” campaign, threat actors published 126 malicious npm packages that have flown under the radar, while collecting 86,000 downloads. Read More  

Share this:

  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on X (Opens in new window) X

Latest Posts

  • From Cyber Security News – Agent Session Smuggling: How Malicious AI Hijacks Victim AgentsNovember 1, 2025
  • From Cyber Security News – Akira Ransomware Allegedly Claims Theft of 23GB in Apache OpenOffice BreachNovember 1, 2025
  • From Cyber Security News – CISA Warns of Linux Kernel Use-After-Free Vulnerability Exploited in Attacks to Deploy RansomwareNovember 1, 2025
  • From Cyber Security News – Hackers Exploiting Cisco IOS XE Vulnerability in the Wild to Deploy BADCANDY Web ShellNovember 1, 2025
  • From Cyber Security News – Hackers Exploiting Windows Server Update Services Flaw to Steal Sensitive Data from OrganizationsNovember 1, 2025