PhantomRaven is a developer-focused software supply chain intrusion campaign centered on the npm ecosystem. The operation is associated with large numbers of malicious npm packages uploaded beginning in August 2025 and designed to compromise developers and build environments. The campaign is notable for abusing Remote Dynamic Dependencies, using URL-based dependency resolution to fetch attacker-controlled code at install time so that malicious logic remains outside the visible package contents and can evade many static-analysis and dependency-inspection tools. Operators also used preinstall execution to run payloads automatically during package installation and could dynamically change payloads over time or selectively serve benign versus malicious content. PhantomRaven targeted developer credentials and secrets, including authentication tokens, GitHub credentials, npm tokens, CI/CD secrets, environment variables, and related system metadata. Reported collection behavior also included developer email addresses, public IP information, and host fingerprinting data. The campaign employed slopsquatting, registering plausible package names likely to be hallucinated or recommended by large language model coding assistants, increasing the chance of accidental installation by developers. This combination of AI-assisted package-name abuse, remote dependency staging, and installation-time execution made the campaign a significant example of modern open-source supply chain tradecraft. The activity has been publicly tracked under the name PhantomRaven. Some reporting later noted claims that related packages were part of a security research experiment, but those claims were disputed due to excessive data collection, lack of transparency, and rotating publisher identities. High-confidence reporting supports treating PhantomRaven as a malicious supply chain campaign targeting developers and software delivery environments. No reliable attribution to a nation-state or specific country of origin is established in the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign involving malicious npm packages uploaded via disposable accounts, using Remote Dynamic Dependencies to deliver mutable payloads that steal environment variables, CI/CD tokens, and system metadata. The attribution is disputed in the content, with claims it may have been a security research experiment.
PhantomRaven is known for registering malicious npm packages with names that are likely to be hallucinated by AI assistants, leading developers to install malware through slopsquatting attacks.
PhantomRaven is conducting a large-scale software supply chain attack campaign targeting the npm registry. The group has published over 100 malicious npm packages designed to steal authentication tokens, CI/CD secrets, and GitHub credentials from developers' machines. The campaign leverages novel techniques to evade detection, such as hiding malicious code in dependencies fetched from attacker-controlled URLs and exploiting slopsquatting to register plausible-sounding package names.
PhantomRaven is a campaign targeting software developers via malicious npm packages to steal credentials and secrets, enabling further supply chain attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.