PhantomRaven is an npm supply-chain malware campaign targeting JavaScript developers through malicious npm packages. Reporting cited here attributes at least 126 malicious npm packages to the campaign, with more than 86,000 installs, and later describes three additional waves from November 2025 to February 2026 involving 88 more malicious packages impersonating established projects including Babel and GraphQL Codegen. The malware is described as stealing developer credentials and secrets, including npm tokens, GitHub credentials, GitHub tokens, GitLab tokens, CircleCI tokens, Jenkins CI/CD tokens, emails from .npmrc and .gitconfig files, environment-variable data, and other CI/CD secrets, while also collecting system details from infected hosts.
A defining technique in PhantomRaven is the use of hidden or remote dynamic dependencies (RDDs): the visible npm package appears benign or may appear to have no dependencies, but during installation npm fetches attacker-controlled code from external infrastructure. The fetched dependency contains a preinstall script that automatically downloads and executes the malicious payload. Koi Security reported the payload infrastructure on packages.storeartifact.com and noted that installation-time requests to that domain helped identify the campaign. The operators reportedly used IP-based targeting to serve benign content to researchers and malicious payloads to intended victims, helping evade static-analysis-based package security tools.
The campaign has also been linked to slopsquatting, where attackers publish plausible package names that may be suggested by LLM-based coding assistants such as GitHub Copilot and ChatGPT. Koi Security traced activity back to August 2025, with infrastructure and payloads remaining broadly consistent across later waves while operators rotated npm accounts, email accounts, package metadata, and PHP endpoints, and increased publication frequency. At the time of reporting, many malicious packages were still available on npm. High-confidence indicators mentioned in the content include the domain packages.storeartifact.com and the fact that Koi Security published package names, an exfiltration URL, and an IP address used for data exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
...exfiltrates emails from .npmrc, .gitconfig... GitHub, GitLab, CircleCI, and Jenkins CI/CD tokens...
...exfiltrates emails from .npmrc, .gitconfig, and environment variables...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware campaign referenced as a prior example of AI-hallucinated naming abuse in malicious npm packages.
A malware campaign that abused AI-invented package names by hiding malware in 126 npm packages.
Malware delivered through malicious npm packages that steals developer-sensitive data, including emails from .npmrc, .gitconfig, and environment variables, CI/CD tokens from GitHub, GitLab, CircleCI, and Jenkins, and system details.
Malicious npm package campaign attributed to PhantomRaven, involving publication of numerous (88) malicious packages to the npm ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.