| Navigation Recherche | Invisible npm malware pulls a disappearing act – then nicks your tokens
	jeudi 30 octobre 2025, 15:19 , par TheRegister
 
PhantomRaven slipped over a hundred credential-stealing packages into npm A new supply chain attack dubbed PhantomRaven has flooded the npm registry with malicious packages that steal credentials, tokens, and secrets during installation. The packages appear safe when first downloaded, making them particularly difficult for security apps to identify.… 
https://go.theregister.com/feed/www.theregister.com/2025/10/30/phantomraven_npm_malware/
 Voir aussi | 56 sources (32 en français) 
 
 Date Actuelle 
			ven. 31 oct. - 15:47 CET	
	
		 | 







 Lire la suite sur TheRegister
Lire la suite sur TheRegister






