NPM Vulnerability Allows 126 Malicious Packages to Be Downloaded 86,000+ Times
By
jnord
Crispy enough to crunch, soft enough to enjoy. A good bake.
Summary
Security researchers have discovered a major vulnerability in NPM (Node Package Manager) that allows attackers to distribute malicious packages through a feature called 'Remote Dynamic Dependencies.' A campaign tracked as PhantomRaven has exploited this weakness to upload 126 credential-stealing packages since August, which have been downloaded over 86,000 times. The vulnerability allows installed packages to automatically download and run unvetted code from untrusted domains, bypassing NPM's security checks.
Key quotes
· 4 pulledAttackers are exploiting a major weakness that has allowed them access to the NPM code repository with more than 100 credential-stealing packages since August, mostly without detection.
Koi said a campaign it tracks as PhantomRaven has exploited NPM's use of 'Remote Dynamic Dependencies' to flood NPM with 126 malicious packages.
Packages downloaded from NPM can fetch dependencies from untrusted sites.
The finding, laid out Wednesday by security firm Koi, brings attention to an NPM practice that allows installed packages to automatically pull down and run unvetted packages from untrusted domains.
You might also wanna read
176 malicious npm packages used dependency confusion to target internal dependencies and steal credentials
Sonatype researchers uncovered a campaign involving 176 malicious npm packages using a dependency confusion attack strategy. Attackers publi

September 2025 NPM supply-chain attack compromises popular JavaScript packages
In September 2025, a coordinated software supply-chain attack targeted multiple popular NPM packages in the JavaScript ecosystem. The attack
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta
Microsoft detects 14 malicious npm packages impersonating OpenSearch and Elasticsearch libraries
A threat actor using the alias vpmdhaj published 14 malicious npm packages within four hours, impersonating legitimate OpenSearch, Elasticse
Microsoft uncovers npm supply chain attack stealing cloud and CI/CD credentials via typosquatted packages
Microsoft identified an active supply chain attack (Mini Shai-Hulud campaign) targeting the npm package ecosystem. On May 28, 2026, a threat
Attacker publishes 14 malicious npm packages impersonating OpenSearch and Elasticsearch libraries
A single npm user published 14 malicious packages over four hours, impersonating popular OpenSearch, Elasticsearch, DevOps, and environment-
