Evidence · DiggingBeagle record
The Return of PhantomRaven: Detecting Three New Waves of npm Supply Chain Attacks
Endor Labs research tracking 88 additional packages across PhantomRaven Waves 2-4 from November 2025 through February 2026. It reports more than 50 disposable npm accounts, correlated infrastructure and payload continuity, later removal of the data-harvesting payload from the studied packages, and the package author's claim that the activity was security research for responsible disclosure or bug-bounty evidence.
- Published
- Mar 10, 2026
- Accessed
- Sep 21, 2026
- Publisher
- Endor Labs
Evidence record
Endor Labs research tracking 88 additional packages across PhantomRaven Waves 2-4 from November 2025 through February 2026. It reports more than 50 disposable npm accounts, correlated infrastructure and payload continuity, later removal of the data-harvesting payload from the studied packages, and the package author's claim that the activity was security research for responsible disclosure or bug-bounty evidence.
Claim-level citations (5)
- contextPhantomRaven used npm packages to deliver an information stealer likely developed with an LLM: CrowdStrike assessed that the operator likely used compromised data to identify bug-bounty opportunities rather than selling stealer logs. Endor Labs separately reported the author's claim that the packages were intended to demonstrate supply-chain vulnerabilities for responsible disclosure or potential bug-bounty reports. Neither source establishes the operator's motive for every PhantomRaven deployment as a directly observed fact.
Update 3/17/2026 describing the author's claimed research and responsible-disclosure intent
- supportsPhantomRaven used npm packages to deliver an information stealer likely developed with an LLM: Koi Security traced the PhantomRaven npm campaign to August 2025, earlier than the November 2025 incidents later described by CrowdStrike.
Timeline: August 2025 campaign begins and first 21 packages are published
- supportsPhantomRaven used npm packages to deliver an information stealer likely developed with an LLM: Endor Labs identified 88 additional packages across Waves 2-4 from November 2025 through February 2026 and reported more than 50 disposable npm accounts while finding the underlying payload largely unchanged across the waves.
Opening findings, Timeline, and Linking the waves sections
- supportsPhantomRaven used npm packages to deliver an information stealer likely developed with an LLM: Endor Labs reported that the package author contacted the researchers in March 2026 and claimed the packages were intended to demonstrate supply-chain vulnerabilities for responsible disclosure or potential bug-bounty reports rather than malicious activity.
Update 3/17/2026 describing the author's contact and stated intent
- supportsPhantomRaven used npm packages to deliver an information stealer likely developed with an LLM: Endor Labs stated that no actual secrets or credentials appeared to have been exfiltrated in the later-wave packages it analyzed; this is a scoped finding and does not establish that no data was exfiltrated anywhere in the PhantomRaven campaign.
Update 3/17/2026 stating that no actual secrets or credentials appeared to have been exfiltrated