Case · DiggingBeagle record

PhantomRaven used npm packages to deliver an information stealer likely developed with an LLM

PhantomRaven is a real-world npm software-supply-chain campaign first publicly traced to August 2025. The campaign used typosquatted or plausible package names and remote URL dependencies to make npm fetch an attacker-controlled package whose install-time script collected developer and CI/CD information. Koi Security initially reported 126 packages and more than 86,000 downloads; Sonatype and Endor Labs later documented additional packages and waves. CrowdStrike subsequently linked specific PhantomRaven activity to a self-described bug-bounty hunter and assessed with high confidence that the JavaScript stealer was likely generated with an LLM. The LLM-authorship and operator-motive findings remain attributed assessments rather than direct model provenance or a campaign-wide proof of intent.

Scope

Real-world software-supply-chain malware campaign documented by CrowdStrike. LLM authorship and operator motive are source assessments, not direct observations of model use or intent.

Assessment profile

Assessment method
Setting
production
Exploitation
observed live
Evidence
Grade B
Remediation
mitigation available
Basis and provenance

Multiple recorded incident-response and package investigations support live malware distribution/execution with contradictory scoped exfiltration outcomes. npm12 defaults mitigate the install path; LLM authorship and bug-bounty motive remain attributed hypotheses. Assessment is a desk review of the retained canonical Claims and cited Source metadata at their recorded cutoff, not a new external verification. Impact remains ungraded.

Assessed Sep 24, 2026 using diggingbeagle.assessment/1.

At a glance

Mechanism and trust boundary

  1. 01

    Publish a lookalike npm package

    The actor publishes a typosquatted package whose visible package content can appear minimal or benign.

    Boundary: developer dependency choice / attacker-controlled package

  2. 02

    Resolve a remote dependency

    The package manifest references a dependency by HTTP URL, causing npm to fetch content from attacker-controlled infrastructure.

    Boundary: package registry metadata / remote attacker infrastructure

  3. 03

    Execute the fetched install script

    The fetched package contains a preinstall script that executes during installation when the npm version and local policy permit it.

    Boundary: dependency installation / local code execution

  4. 04

    Collect developer and CI/CD data

    The stealer reads system data, Git and npm configuration, package metadata and CI/CD environment variables.

    Boundary: local execution / developer and build credentials

  5. 05

    Exfiltrate collected data

    PhantomRaven sends collected data to attacker-controlled command-and-control infrastructure over HTTP.

    Boundary: developer environment / external command and control

Timeline

  1. 2025-08 (month precision)
    Event type unspecified

    PhantomRaven campaign begins

    Koi Security traced the first PhantomRaven packages to August 2025; Endor Labs later summarized the first 21 packages as published and removed during that month.

  2. Oct 29, 2025
    Event type unspecified

    Koi Security publishes the first public PhantomRaven disclosure

    Koi reported 126 malicious npm packages and more than 86,000 downloads.

  3. Oct 31, 2025
    Event type unspecified

    Sonatype expands the known package set

    Sonatype reported 83 additional packages associated with the campaign, bringing the reported total above 200.

  4. 2025-11 (month precision)
    Event type unspecified

    CrowdStrike observes PhantomRaven incidents and victim contact

    CrowdStrike reports that the operator contacted a potential victim organization in November 2025 and that Falcon Complete responded to and remediated multiple PhantomRaven incidents.

  5. Nov 13, 2025 to Feb 10, 2026
    Event type unspecified

    Wave 2

    Endor Labs tracked 50 Wave-2 packages published across more than 26 npm accounts.

  6. Feb 13, 2026 to Feb 17, 2026
    Event type unspecified

    Wave 3

    Endor Labs tracked 34 packages across more than 25 npm accounts during a five-day burst.

  7. Feb 18, 2026
    Event type unspecified

    Wave 4

    Endor Labs tracked four Wave-4 packages published on the same day.

  8. Mar 10, 2026
    Event type unspecified

    Endor Labs publishes analysis of Waves 2-4

    Endor Labs reported 88 additional packages, more than 50 disposable npm accounts, and infrastructure/payload continuity across four waves.

  9. Mar 12, 2026
    mitigation

    Later-wave data-harvesting payload is removed

    Endor Labs reported that the Wave-2 remote package had been replaced with a minimal Hello World script and that data collection across the 88 studied later-wave packages was effectively neutralized without npm package updates.

  10. Mar 17, 2026
    Event type unspecified

    Package author disputes malicious intent

    Endor Labs reported that the author contacted researchers and said the packages were intended to demonstrate supply-chain vulnerabilities for responsible disclosure or bug-bounty reports; Endor stated that no actual secrets or credentials appeared to have been exfiltrated in the later-wave packages it analyzed.

  11. Jun 9, 2026
    mitigation

    npm announces v12 install-time security defaults

    GitHub announced upcoming npm v12 defaults that would disable dependency lifecycle scripts and remote URL dependencies unless explicitly allowed.

  12. Jul 8, 2026
    mitigation

    npm v12 becomes generally available

    GitHub announced npm v12 as generally available with allowScripts off and remote URL dependencies opt-in by default.

  13. Sep 15, 2026
    Event type unspecified

    CrowdStrike publishes attribution and LLM-authorship assessment

    CrowdStrike linked specific npm accounts and infrastructure to a self-described bug-bounty hunter, documented multiple remediated incidents, and assessed with high confidence that the JavaScript stealer was likely LLM-generated.

Claims & evidence

CLM-PHANTOMRAVEN-LLMCrowdStrike assessed with high confidence that PhantomRaven was likely developed using a large language model, citing verbose comments, placeholder code and statistical token-analysis patterns.supported

Basis: reported finding

Link to claim
CLM-PHANTOMRAVEN-SCALEThe initial public disclosure identified 126 malicious npm packages with more than 86,000 downloads; Sonatype then reported 83 additional packages, bringing the known package count above 200. These figures measure package/download scale, not confirmed victims.supported

Basis: reported finding

Link to claim
CLM-PHANTOMRAVEN-MOTIVECrowdStrike assessed that the operator likely used compromised data to identify bug-bounty opportunities rather than selling stealer logs. Endor Labs separately reported the author's claim that the packages were intended to demonstrate supply-chain vulnerabilities for responsible disclosure or potential bug-bounty reports. Neither source establishes the operator's motive for every PhantomRaven deployment as a directly observed fact.supported

Basis: reported finding

Link to claim
CLM-PHANTOMRAVEN-INCIDENTSCrowdStrike Falcon Complete responded to and remediated multiple incidents involving PhantomRaven and identified two npm packages containing PhantomRaven scripts: transform-jsbi-to-bigint and sort-imports-es6-autofix.supported

Basis: reported finding

Link to claim
CLM-PHANTOMRAVEN-COLLECTIONPhantomRaven collected host and developer-environment data including Git and npm configuration information and CI/CD-related environment variables that could contain authentication tokens and API keys, then exfiltrated collected data over HTTP.supported

Basis: reported finding

Link to claim
CLM-PHANTOMRAVEN-FIRST-SEENKoi Security traced the PhantomRaven npm campaign to August 2025, earlier than the November 2025 incidents later described by CrowdStrike.supported

Basis: reported finding

Link to claim
CLM-PHANTOMRAVEN-LATER-WAVESEndor Labs identified 88 additional packages across Waves 2-4 from November 2025 through February 2026 and reported more than 50 disposable npm accounts while finding the underlying payload largely unchanged across the waves.supported

Basis: reported finding

Link to claim
CLM-PHANTOMRAVEN-DISTRIBUTIONThe PhantomRaven operator distributed malware through typosquatted npm packages that declared HTTP URL dependencies pointing to attacker-controlled infrastructure; the fetched package contained a preinstall script that executed the information stealer when installation scripts were permitted.supported

Basis: reported finding

Link to claim
CLM-PHANTOMRAVEN-ACTOR-ALIASESCrowdStrike assessed with high confidence that the npm accounts jpdhellonpm1 and jpd15 were operated by the same PhantomRaven actor.supported

Basis: reported finding

Link to claim
CLM-PHANTOMRAVEN-NPM12-MITIGATIONnpm v12, generally available on July 8, 2026, changed install-time defaults so dependency lifecycle scripts and remote URL dependencies are opt-in rather than automatically trusted, directly reducing the default execution path used by PhantomRaven.supported

Basis: reported finding

Link to claim
CLM-PHANTOMRAVEN-OPERATOR-RESPONSEEndor Labs reported that the package author contacted the researchers in March 2026 and claimed the packages were intended to demonstrate supply-chain vulnerabilities for responsible disclosure or potential bug-bounty reports rather than malicious activity.supported

Basis: allegation

Link to claim
CLM-PHANTOMRAVEN-LATER-WAVE-EXFILTRATIONEndor Labs stated that no actual secrets or credentials appeared to have been exfiltrated in the later-wave packages it analyzed; this is a scoped finding and does not establish that no data was exfiltrated anywhere in the PhantomRaven campaign.supported

Basis: reported finding

Link to claim

Implications

PhantomRaven is best understood as a long-running software-supply-chain campaign rather than a single November 2025 event. Its security significance comes from the combination of package-name deception, npm's historical willingness to resolve remote URL dependencies, mutable second-stage payloads outside the registry package body, and install-time code execution inside developer and CI/CD environments. AI appears in two distinct roles that should not be conflated: Koi documented slopsquatting that exploits hallucinated or plausible package names, while CrowdStrike later assessed with high confidence that the JavaScript stealer itself was likely LLM-generated. The campaign also shows why exposure counts, successful exfiltration, downstream compromise, and financial damage must be recorded separately: 86,000+ downloads do not equal 86,000 victims, and Endor Labs' later-wave no-secret-exfiltration finding does not erase CrowdStrike's documented incidents.

Controls and mitigations

  • Use npm 12 or later so dependency lifecycle scripts and remote URL dependencies are not automatically trusted by default; review any explicit exceptions carefully.
  • Use a controlled private npm registry or dependency allowlisting for sensitive development and build environments.
  • Use --ignore-scripts where workflows permit, enabling lifecycle scripts only for dependencies that have been explicitly reviewed.
  • Review package manifests and lockfiles for URL-based dependencies and unexpected non-registry fetches.
  • Treat typosquatted, brandjacked, and AI-suggested package names as untrusted until the package identity and provenance are verified.
  • Monitor outbound network activity from dependency installation and CI/CD jobs for unexpected external package or C2 hosts.
  • After suspected exposure, rotate npm tokens, Git/source-control credentials, CI/CD tokens, API keys, and other secrets that were available to the affected process or build environment.

Unknowns and contradictions

  • The complete count and identities of organizations affected by confirmed PhantomRaven execution are not public.
  • No authoritative source reviewed provides a quantified financial-loss total attributable to PhantomRaven.
  • The relationship between the 86,000+ package downloads and actual execution, data collection, credential exposure, or downstream compromise is not quantified.
  • Endor Labs found no actual secrets or credentials appeared to have been exfiltrated in the later waves it studied, while CrowdStrike later documented multiple real incidents; campaign-wide exfiltration outcomes remain unresolved.
  • The amount of bug-bounty revenue, if any, that resulted specifically from PhantomRaven-enabled compromises has not been established.
  • The specific LLM or provider used to generate the malware has not been identified through direct provenance.
  • CrowdStrike's linkage of specific npm monikers is high confidence, but a single end-to-end attribution covering every package reported by Koi, Sonatype, Endor Labs, and later researchers is not established in the reviewed sources.

Sources and citation

Material revision history

  1. Sep 25, 2026 · Canonical change recorded · new in release · revision 39