CrowdStrike identified PhantomRaven, a JavaScript information-stealer campaign attributed to a likely low-sophistication eCrime actor tracked as JPD. The actor distributed typosquatted npm packages that use HTTP-based remote dynamic dependencies: during installation, npm retrieves a malicious dependency whose preinstall script automatically executes the payload.
The stealer collects host and runtime details, Git and npm configuration, and CI/CD environment data that can expose developer credentials, then exfiltrates the information through HTTP GET and POST requests to attacker-controlled infrastructure. JPD may also be connected to PyPI-hosted stealer code and may have sought bug-bounty payouts using compromised data. npm 12 and later blocks dependency-install scripts by default unless explicitly approved, reducing exposure to this execution technique.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
A PhantomRaven campaign used techniques resembling the actor's claimed RCE method, using HTTP-hosted remote dependencies that retrieved a malicious package and executed its preinstall script during npm installation. The domain npm[.]jpartifacts[.]com was used for command-and-control activity.
The actor claimed to have obtained remote code execution by publishing a malicious npm package with a preinstall script; the claim was not independently verified.
The threat actor's GitHub account submitted an issue to PyPI concerning an unsuccessful package upload.
CrowdStrike associated the likely low-sophistication eCrime actor JPD with PhantomRaven deployments, citing linked npm identities, PyPI-hosted code, and infrastructure. It assessed with high confidence that the PhantomRaven code was almost certainly LLM-generated and with moderate confidence that the actor sought company access potentially to support bug-bounty reward claims.
A PyPI organization member accused the actor of attempting to build an information stealer and linked to the actor's main project, which was later removed from PyPI. Associated Python files remained accessible and contained stealer code similar to PhantomRaven.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.