Key Takeaways: PhantomRaven attack is an npm supply chain attack targeting CI/CD secrets and developer credentials (developer credential theft). The malware hides outside the npm registry using Remote Dynamic Dependencies (RDD). Most static analysis and SBOM tools could not detect the hidden payload. Attackers used fake package names. GitHub Actions, GitLab CI, Jenkins, CircleCI, and …
|
|



