Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Check Out The Latest Events In ‘Marvel Future Fight’ & ‘Marvel Contest of Champions’

    March 31, 2026

    Surreal Satire Meets Bedroom Chaos

    March 31, 2026

    BMW iX3 Long Wheelbase Debuts With Different Door Handles — Here’s Why

    March 31, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»NPM flooded with malicious packages downloaded more than 86,000 times
    NPM flooded with malicious packages downloaded more than 86,000 times
    Tech Reviews

    NPM flooded with malicious packages downloaded more than 86,000 times

    gvfx00@gmail.comBy gvfx00@gmail.comOctober 30, 2025No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Attackers are exploiting a major weakness that has allowed them access to the NPM code repository with more than 100 credential-stealing packages since August, mostly without detection.

    The finding, laid out Wednesday by security firm Koi, brings attention to an NPM practice that allows installed packages to automatically pull down and run unvetted packages from untrusted domains. Koi said a campaign it tracks as PhantomRaven has exploited NPM’s use of “Remote Dynamic Dependences” to flood NPM with 126 malicious packages that have been downloaded more than 86,000 times. Some 80 of those packages remained available as of Wednesday morning, Koi said.

    Table of Contents

    Toggle
    • A blind spot
      • Related posts:
    • Micron 3610: 1st QLC Gen 5 SSD is Cool
    • 'I thought this video was an April Fool's joke, but it's still March': Nvidia reveals DLSS 5 to supe...
    • What is the release date for Bridgerton season 4 part 1 on Netflix?

    A blind spot

    “PhantomRaven demonstrates how sophisticated attackers are getting [better] at exploiting blind spots in traditional security tooling,” Koi’s Oren Yomtov wrote. “Remote Dynamic Dependencies aren’t visible to static analysis.”

    Remote Dynamic Dependencies provide greater flexibility in accessing dependencies—the code libraries that are mandatory for many other packages to work. Normally, dependencies are visible to the developer installing the package. They’re usually downloaded from NPM’s trusted infrastructure.

    RDD works differently. It allows a package to download dependencies from untrusted websites, even those that connect over HTTP, which is unencrypted. The PhantomRaven attackers exploited this leniency by including code in the 126 packages uploaded to NPM. The code downloads malicious dependencies from URLs, including http://packages.storeartifact.com/npm/unused-imports. Koi said these dependencies are “invisible” to developers and many security scanners. Instead, they show the package contains “0 Dependencies.” An NPM feature causes these invisible downloads to be automatically installed.

    Compounding the weakness, the dependencies are downloaded “fresh” from the attacker server each time a package is installed, rather than being cached, versioned, or otherwise static, as Koi explained:

    Related posts:

    'They're as robust as they can be while being comfortable for most users': a Dyson engineer reveals ...

    LG's OLED TVs get certified as the contrast king even over RGB TV tech in tests, though we have some...

    I Saw a Hidden Induction Stove Concept at KBIS. It Looked Cool and Very Dangerous

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleIBMs släpper öppen källkod Granite 4.0 Nano – kompakt LLM för laptop och mobil
    Next Article Generative AI Hype Check: Can It Really Transform SDLC?
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    World Backup Day: 100% Solid Tips on Safeguarding Your Data

    March 31, 2026
    Tech Reviews

    BOXROOM lets you build a cozy game room for your Steam library

    March 31, 2026
    Tech Reviews

    Google Gemini’s Headphone Live Translation Arrives on Apple Devices

    March 30, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025137 Views

    BMW Will Put eFuel In Cars Made In Germany From 2028

    October 14, 202511 Views

    Best Sonic Lego Deals – Dr. Eggman’s Drillster Gets Big Price Cut

    December 16, 20259 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025137 Views

    BMW Will Put eFuel In Cars Made In Germany From 2028

    October 14, 202511 Views

    Best Sonic Lego Deals – Dr. Eggman’s Drillster Gets Big Price Cut

    December 16, 20259 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.