security1 publisher
PhantomRaven hid its credential stealer in an npm dependency that scanners never fetch
Koi Security counted 126 npm packages and more than 86,000 installs since August 2025, with 80 still live when it published. npm pulled the stealer from the attacker's host at install time. That put it outside the package a scanner reads.
Publishers:web.archive.org
Reality
- Evidence58
- Adoption52
- Hype gap+22
- Incentives74
- Confidence51