CrowdStrike identified PhantomRaven, a JavaScript information-stealer campaign attributed to a likely low-sophistication eCrime actor tracked as JPD. The actor distributed typosquatted npm packages that use HTTP-based remote dynamic dependencies: during installation, npm retrieves a malicious dependency whose preinstall script automatically executes the payload.
The stealer collects host and runtime details, Git and npm configuration, and CI/CD environment data that can expose developer credentials, then exfiltrates the information through HTTP GET and POST requests to attacker-controlled infrastructure. JPD may also be connected to PyPI-hosted stealer code and may have sought bug-bounty payouts using compromised data. npm 12 and later blocks dependency-install scripts by default unless explicitly approved, reducing exposure to this execution technique.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
CrowdStrike published technical details of PhantomRaven, reporting that typosquatted npm packages used remote dynamic dependencies and preinstall scripts to retrieve and execute the JavaScript stealer. The report documented collection of host, CI/CD, Git, and npm configuration data, HTTP GET/POST exfiltration, and additional C2 infrastructure and file hashes.
A PhantomRaven campaign used techniques resembling the actor's claimed RCE method, using HTTP-hosted remote dependencies that retrieved a malicious package and executed its preinstall script during npm installation. The domain npm[.]jpartifacts[.]com was used for command-and-control activity.
Koi Security and DCODX first identified the PhantomRaven JavaScript information-stealer campaign in late October 2025. The campaign used slopsquatting and typosquatting to distribute more than 100 malicious npm packages.
The actor claimed to have obtained remote code execution by publishing a malicious npm package with a preinstall script; the claim was not independently verified.
The threat actor's GitHub account submitted an issue to PyPI concerning an unsuccessful package upload.
CrowdStrike associated the likely low-sophistication eCrime actor JPD with PhantomRaven deployments, citing linked npm identities, PyPI-hosted code, and infrastructure. It assessed with high confidence that the PhantomRaven code was almost certainly LLM-generated and with moderate confidence that the actor sought company access potentially to support bug-bounty reward claims.
A PyPI organization member accused the actor of attempting to build an information stealer and linked to the actor's main project, which was later removed from PyPI. Associated Python files remained accessible and contained stealer code similar to PhantomRaven.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
mkd-cirt.mk
Open sourcecyberveille.ch
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.