Phantom Bot is a Go-based DDoS botnet payload delivered via the malicious npm package axois-utils in a broader npm supply-chain/typosquatting campaign attributed to the same publisher that distributed multiple malicious packages. The malware is explicitly referred to in the package as a “phantom bot.” Its documented capabilities include flooding targets using HTTP, TCP, UDP, and reset requests, turning infected systems into DDoS nodes. Reported persistence mechanisms allow it to remain on infected machines even after the npm package is deleted; supporting reporting states this persistence is achieved on Windows by adding the payload to the Windows Startup folder and on Linux by creating a scheduled task. The campaign was identified by OX Security and involved packages published by the npm user deadcode09284814 alongside other stealer payloads. High-confidence context indicates the overall campaign targeted npm users and was assessed as financially motivated, while the DDoS capability also raised the possibility of disruptive or DDoS-for-hire use. No Phantom Bot-specific C2 or unique IOC beyond delivery through axois-utils is directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based bot payload delivered via a malicious npm package that establishes persistence and turns infected systems into a DDoS botnet capable of HTTP, TCP, UDP, and reset-request flooding.
Golang-based DDoS botnet capable of flooding targets over HTTP, TCP, and UDP. It also establishes persistence on Windows and Linux systems.
Go-based DDoS botnet payload delivered via a malicious npm package. It floods targets with HTTP, TCP, UDP, and Reset requests and uses persistence to remain on infected machines after package deletion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.