remote-dynamic-dependencies

1 article
sort: new top best
clear filter
0 5/10

PhantomRaven is an ongoing supply-chain campaign distributing 88+ malicious npm packages using typosquatting and Remote Dynamic Dependencies (RDD) to evade detection. The malware steals CI/CD tokens, credentials, and system information from developers, exfiltrating data to attacker-controlled C2 servers.

PhantomRaven Koi Endor Labs npm Babel GraphQL Codegen GitHub GitLab Jenkins CircleCI Amazon EC2 Bill Toulas
bleepingcomputer.com · Bill Toulas · 2 days ago · details