PhantomRaven: Hidden NPM Malware Exploits Remote Dynamic Dependencies
Koi Security discovered PhantomRaven campaign compromising 86,000+ npm downloads via Remote Dynamic Dependencies (RDD)—an obscure npm feature allowing HTTP URLs as package dependencies. What's clever:…
Category: Threat Alerts / Supply Chain / Supply Chain