Threat Actor Uses AI to Develop Malware Distributed via npm Repository
A financially motivated threat actor has been linked to developing and distributing PhantomRaven, a JavaScript-based information stealer spread through…
Audit npm dependencies in your development inventory to detect PhantomRaven; review recent package updates you use. Implement software supply chain integrity controls and consider restrictions on which packages can be installed in production environments.