PhantomSync is a malicious npm package cluster focused on cryptocurrency wallet theft and developer secret harvesting. The operation used eight npm packages masquerading as legitimate blockchain, wallet, and development utilities. Each package exposed expected functionality while also embedding delayed, import-triggered malicious code that decoded and launched a second-stage stealer, established cross-platform persistence, and continued running as a detached background process. The second stage, identified as a variant of "phantom syncd v3," targeted cryptocurrency and developer material including seed phrases, private keys, keystore files, Solana keypairs, SSH keys, and secret-bearing environment variables. It searched user home directories and platform-specific application data locations associated with wallet software and development tooling. Variants differed in collection logic, with some using regex and embedded BIP-39 validation to extract wallet secrets from text, while others matched likely wallet-related files by keyword and uploaded entire files. PhantomSync incorporated multiple post-compromise controls intended to reduce detection and improve operator control. It delayed initial execution after module import, waited for user idle time before harvesting data, checked a remotely controlled activation switch, and used fallback retrieval paths when the primary control channel was unavailable. It established persistence across Linux, macOS, and Windows using native scheduled execution mechanisms and periodically re-established that persistence. Collected data was encrypted with an embedded RSA-4096 public key before exfiltration to public IPFS storage through a pinning service. The malware also maintained a local record of uploads. The campaign is best characterized as a software supply chain operation targeting developers and cryptocurrency users through open-source package ecosystems. Known aliases directly supported at high confidence are limited to PhantomSync.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious npm supply-chain campaign using eight packages that appear functional but contain a delayed self-invoking dropper, install cross-platform persistence, and deploy a crypto-wallet and secrets stealer that exfiltrates RSA-4096-encrypted data to public IPFS storage.
A malicious npm supply-chain activity cluster in which a single publisher shipped eight packages containing delayed import-time droppers that decode and launch a second-stage crypto-wallet and secrets stealer with cross-platform persistence and IPFS-based exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.