An active campaign named 'PhantomRaven' is targeting developers with dozens of malicious npm packages that steal authentication tokens, CI/CD secrets, and GitHub credentials.
Recently, security researchers Socket found 10 packages on npm targeting software developers, specifically those who use the ...