PhantomRaven is a JavaScript-based information stealer targeting developers through the npm software supply chain. It is distributed in typosquatted and slopsquatted packages that appear benign but retrieve a malicious remote dynamic dependency during installation. The fetched dependency uses an installation lifecycle script to execute automatically. PhantomRaven harvests host and runtime information, Git and npm configuration data, developer usernames and email addresses, and CI/CD environment variables associated with GitHub Actions, GitLab CI, Jenkins, and CircleCI, potentially exposing authentication tokens, API keys, and other secrets. It exfiltrates collected data over HTTP. The activity has been linked to a financially motivated operator tracked as the PhantomRaven Operator, also known as JPD, which has targeted JavaScript developers and organizations in technology, retail, and hospitality sectors. Similar information-stealer code has also been associated with attempted distribution through PyPI.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PhantomRaven est un infostealer JavaScript distribué via des paquets npm typosquattés utilisant une dépendance dynamique distante et un script preinstall.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
“These packages aimed to steal authentication tokens, CI/CD secrets, and GitHub credentials from developers.”
Пакетите имале цел „да крадат автентикациски токени, CI/CD тајни и GitHub акредитиви“ и собирале „променливите на околината ... за CI/CD системите GitHub Actions, GitLab CI, Jenkins и CircleCI“ и email адреси од Git/npm конфигурации.
Системскиот отпечаток вклучува „јавната IP адреса“.
PhantomRaven contacte «https://api64.ipify.org?format=json» pour déterminer l’IP externe.
“Once installed, PhantomRaven collects sensitive information including email addresses, CI/CD environment details, and system fingerprints.”
«L’exfiltration s’effectue via des requêtes HTTP GET et POST vers l’infrastructure C2.»
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript-based information stealer distributed through typosquatted and slopsquatted npm packages. It uses a remote dynamic dependency to evade security tools, collects authentication tokens, CI/CD secrets, GitHub credentials, email addresses, CI/CD environment details, and system fingerprints, then exfiltrates them to an attacker-controlled server. The activity appears primarily intended to identify bug-bounty opportunities.
JavaScript-based npm supply-chain information stealer that collects developer email addresses, Git/npm configuration data, CI/CD secrets and environment variables, runtime and system-fingerprint information including public IP address, then exfiltrates the results to an attacker-controlled server. The operator reportedly used it to identify bug-bounty opportunities.
Infostealer JavaScript distribué par supply-chain npm. Lors de l’installation d’un paquet compromis, il collecte les informations système, l’adresse IP locale et externe, le répertoire courant, le PID, les variables d’environnement CI/CD, ainsi que les configurations Git et npm (notamment email et nom d’utilisateur). Les données sont exfiltrées via des requêtes HTTP GET et POST vers une infrastructure C2 contrôlée par l’attaquant.
Named malware campaign referenced as a prior example of AI-hallucinated naming abuse in malicious npm packages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.