{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreihic3w5uqk5b2fqylr2tbjfw3qnaokhlq66sikmigjizwneyrdl6a",
"uri": "at://did:plc:6wtxqaikjf62unmnajbfbq5v/app.bsky.feed.post/3mgw44sdnzhd2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreihw6ckowpklrg3a755azfpetmde7y3vzpvpqqdbxsxc7wpwv7uxnu"
},
"mimeType": "image/webp",
"size": 23596
},
"path": "/new-phantomraven-npm-wave-uses-88-malicious-packages-to-steal-developer-secrets/",
"publishedAt": "2026-03-12T08:40:43.000Z",
"site": "https://vpncentral.com",
"tags": [
"News",
"New PhantomRaven npm wave uses 88 malicious packages to steal developer secrets",
"VPN Central"
],
"textContent": "A new wave of the PhantomRaven supply-chain campaign has hit the npm ecosystem, with Endor Labs identifying 88 malicious packages spread across three attack waves between November 2025 and February 2026. The researchers say the packages steal sensitive data from developers, including emails, system details, and CI/CD tokens, and that 81 of the 88 packages […]\n\nThe post New PhantomRaven npm wave uses 88 malicious packages to steal developer secrets appeared first on VPN Central.",
"title": "New PhantomRaven npm wave uses 88 malicious packages to steal developer secrets"
}