By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
The Tech DiffThe Tech DiffThe Tech Diff
  • Home
  • Shop
  • Computers
  • Phones
  • Technology
  • Wearables
Reading: “NPM Breached: Malicious Packages Downloaded Over 86,000 Times”
Share
Font ResizerAa
The Tech DiffThe Tech Diff
Font ResizerAa
  • Computers
  • Phones
  • Technology
  • Wearables
Search
  • Home
  • Shop
  • Computers
  • Phones
  • Technology
  • Wearables
Follow US
  • Shop
  • About
  • Contact
  • Terms & Conditions
  • Privacy Policy
© Copyright 2022. All Rights Reserved By The Tech Diff.
The Tech Diff > Blog > Technology > “NPM Breached: Malicious Packages Downloaded Over 86,000 Times”
Technology

“NPM Breached: Malicious Packages Downloaded Over 86,000 Times”

Admin
Last updated: October 30, 2025 9:13 am
Admin
Share
“NPM Breached: Malicious Packages Downloaded Over 86,000 Times”
SHARE

Contents
An Alarming DiscoveryA Vulnerability ExposedThe Attack MechanismEscalating Risks

In recent months, a significant vulnerability in the Node Package Manager (NPM) code repository has come to light, drawing the attention of security experts. A security firm named Koi has revealed that attackers have exploited this weakness, resulting in over 100 credential-stealing packages infiltrating the platform. Since August, this malicious campaign has largely gone undetected, posing a serious risk to developers and the software ecosystem as a whole.

-31% BERIBES Bluetooth Headphones: 65H Playtime & Deep Bass!
Headphones

BERIBES Bluetooth Headphones: 65H Playtime & Deep Bass!

$28.99 Original price was: $28.99.$19.99Current price is: $19.99.
Buy Now
Boost Storage: Amazon Basics 256GB Micro SDXC, 100MB/s!
Computer & Accessories

Boost Storage: Amazon Basics 256GB Micro SDXC, 100MB/s!

$19.79
Buy Now
-10% Unleash Precision with ATTACK SHARK X3 Wireless Gaming Mouse!
Computer & Accessories

Unleash Precision with ATTACK SHARK X3 Wireless Gaming Mouse!

$41.99 Original price was: $41.99.$37.79Current price is: $37.79.
Buy Now
-90% Unleash Your Workout: NDO Bluetooth 5.3 Waterproof Earbuds!
Headphones

Unleash Your Workout: NDO Bluetooth 5.3 Waterproof Earbuds!

$229.99 Original price was: $229.99.$22.99Current price is: $22.99.
Buy Now

An Alarming Discovery

Koi’s findings highlight a troubling aspect of NPM’s operational framework, particularly its practice of allowing installed packages to fetch and execute unverified dependencies from untrusted domains. This approach has been leveraged by cybercriminals in a campaign referred to as PhantomRaven. By exploiting NPM’s “Remote Dynamic Dependencies” (RDD), these attackers have uploaded 126 malicious packages that have collectively been downloaded over 86,000 times. Alarmingly, Koi reported that approximately 80 of these packages were still available for download as of Wednesday morning.

A Vulnerability Exposed

Oren Yomtov, a representative from Koi, remarked, “PhantomRaven demonstrates how sophisticated attackers are getting [better] at exploiting blind spots in traditional security tooling.” He emphasized that the Remote Dynamic Dependencies employed in these packages are not visible to standard static analysis tools, allowing the attackers to evade detection effectively.

Remote Dynamic Dependencies offer developers increased flexibility by enabling packages to download essential code libraries—dependencies—required for their functionality. Typically, these dependencies are fetched from NPM’s trusted infrastructure, ensuring a degree of safety. However, the RDD mechanism operates differently by permitting packages to pull dependencies from untrusted and even unencrypted HTTP sources.

The Attack Mechanism

In the case of the PhantomRaven campaign, malicious code embedded within the 126 uploaded packages instructs them to download dangerous dependencies from external URLs, such as http://packages.storeartifact.com/npm/unused-imports. Koi has highlighted that these pernicious dependencies are often invisible to developers and conventional security scanners, misleading them into believing that the package contains “0 Dependencies.” As a result of a built-in NPM feature, these hidden downloads are automatically installed whenever a user sets up the package.

Escalating Risks

What exacerbates this vulnerability is that each time a package is installed, the dependencies are fetched freshly from the attacker’s server, rather than being cached or versioned in a static manner. This makes it incredibly difficult for developers to maintain control over the integrity of their code and introduces an ongoing risk of infection.

The exploitation of Remote Dynamic Dependencies presents a critical challenge for developers relying on NPM for their projects. The broader implications are significant, as the ease with which attackers can manipulate unverified sources raises concerns about trust and security within the software supply chain.

For those interested in further details, more information can be found in the original article by Koi Here.

Image Credit: arstechnica.com

You Might Also Like

Microsoft Recovers from Azure Outage Affecting 365, Xbox, and Starbucks

“Enshittification: Why Google, Amazon, and Facebook Are Now Worse”

“LG Uplus Confirms Latest Cybersecurity Incident in South Korea”

“AGI Arrival to Be Decided by Expert Panel in Microsoft-OpenAI Deal”

“DJI Unveils Romo: The Future of Robot Vacuum Technology”

Share This Article
Facebook Twitter Copy Link Print
Previous Article iQOO Unveils Neo11’s Powerful New Chipset iQOO Unveils Neo11’s Powerful New Chipset
Next Article “Black Friday Gaming PC Discounts in October: Unmissable UK Deals!” “Black Friday Gaming PC Discounts in October: Unmissable UK Deals!”
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Product categories

  • Computer & Accessories
  • Headphones
  • Laptops
  • Phones
  • Wearables

Trending Products

  • Powerful Dell 15 3530: Ultimate Business & Student Laptop! Powerful Dell 15 3530: Ultimate Business & Student Laptop! $899.00
  • ARZOPA 16.1” 144Hz Monitor: Ultimate Portable Gaming Upgrade! ARZOPA 16.1'' 144Hz Monitor: Ultimate Portable Gaming Upgrade! $139.99 Original price was: $139.99.$109.99Current price is: $109.99.
  • Unlock Versatility: 16″ Convertible Laptop with FHD Touchscreen! Unlock Versatility: 16" Convertible Laptop with FHD Touchscreen! $1,333.18 Original price was: $1,333.18.$399.99Current price is: $399.99.
  • SAMSUNG Galaxy S24 Ultra 5G: Power, Speed & Style! SAMSUNG Galaxy S24 Ultra 5G: Power, Speed & Style! $432.95
  • Lenovo IdeaPad Slim 3i: Power & Portability in Arctic Grey! Lenovo IdeaPad Slim 3i: Power & Portability in Arctic Grey! $1,299.99 Original price was: $1,299.99.$298.00Current price is: $298.00.

You Might also Like

“AI Transforms Medicine: Uniting Doctors and Patients for Better Care”
Technology

“AI Transforms Medicine: Uniting Doctors and Patients for Better Care”

Admin Admin 4 Min Read
“Feds Seize  Billion From Alleged Human Trafficking Operation”
Technology

“Feds Seize $15 Billion From Alleged Human Trafficking Operation”

Admin Admin 3 Min Read
“Listen to the Brutal Truth of ‘I’ve Seen All I Need to See’”
Technology

“Listen to the Brutal Truth of ‘I’ve Seen All I Need to See’”

Admin Admin 4 Min Read

About Us

At The Tech Diff, we believe technology is more than just innovation—it’s a lifestyle that shapes the way we work, connect, and explore the world. Our mission is to keep readers informed, inspired, and ahead of the curve with fresh updates, expert insights, and meaningful stories from across the digital landscape.

Useful Link

  • Shop
  • About
  • Contact
  • Terms & Conditions
  • Privacy Policy

Categories

  • Computers
  • Phones
  • Technology
  • Wearables

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

The Tech DiffThe Tech Diff
Follow US
© Copyright 2022. All Rights Reserved By The Tech Diff.
Welcome Back!

Sign in to your account

Lost your password?