Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI-Assisted Malware Targets npm Users with PhantomRaven

AI-Assisted Malware Targets npm Users with PhantomRaven

Posted on September 18, 2026 By CWS

A financially driven cybercriminal group has been linked to the creation and dissemination of PhantomRaven, a JavaScript-based malware. This malicious software is being distributed through the npm package registry, targeting developers to extract sensitive information.

Development and Distribution of PhantomRaven

According to CrowdStrike’s Counter Adversary Operations, the malware was likely crafted using a large language model (LLM). This conclusion is based on detailed analysis, including verbose comments, placeholder code, and statistical patterns within the code. PhantomRaven was initially identified by Koi Security and DCODX in late October 2025, highlighting a campaign involving over 100 malicious npm packages designed to steal authentication tokens, CI/CD secrets, and GitHub credentials.

These packages act as a conduit to fetch a remote dynamic dependency (RDD) from an external server, making it difficult for security tools to detect the libraries as threats. Once operational, the malware scans developer environments for email addresses, collects CI/CD environment data, and gathers system fingerprints, including public IP addresses, all of which are sent to a server controlled by the attacker.

Impact on Software Supply Chain

The malware is also capable of obtaining runtime details, dates, times, and user information from Git/npm configurations, along with CI/CD environment variables for platforms like GitHub Actions, GitLab CI, Jenkins, and CircleCI. CrowdStrike’s recent findings reveal that the threat actor has been active since November 2022, posing as a bug bounty hunter and claiming to have earned rewards from at least nine different organizations in sectors such as technology, retail, and hospitality.

No stolen data from this malware has been found on stealer log markets, suggesting that the attacker uses the stolen information solely to find bug bounty opportunities. Two npm accounts associated with the attacker, used to distribute PhantomRaven, are now inaccessible.

Expanding Operations and Future Threats

Additional online aliases linked to this operation include jpd12, jpd13, npmhell, and others. In August 2025, the threat actor reportedly discovered a remote code execution (RCE) vulnerability through a malicious npm package they released. This was achieved by compromising a target machine and executing a preinstall script to enable RCE.

Furthermore, there is evidence that the threat actor attempted to extend their operations to the Python Package Index (PyPI) repository with similar malware. The use of a large language model to develop PhantomRaven emphasizes the growing trend of cybercriminals leveraging AI technologies to streamline their malicious activities.

CrowdStrike noted that while many cybercriminals rent or develop their own proprietary malware, this particular actor has likely created PhantomRaven to infiltrate company systems and use these breaches to claim rewards from legitimate disclosure programs.

The Hacker News Tags:AI malware, bug bounty, CrowdStrike, Cybercrime, Cybersecurity, JavaScript malware, LLM, npm security, PhantomRaven, supply chain attack

Post navigation

Previous Post: Critical Flaws in BIND DNS Servers Threaten Security
Next Post: Critical Vulnerabilities Patched by Top Cybersecurity Firms

Related Posts

DOM-Based Extension Clickjacking Exposes Popular Password Managers to Credential and Data Theft DOM-Based Extension Clickjacking Exposes Popular Password Managers to Credential and Data Theft The Hacker News
ShadowV2 Botnet Exploits Misconfigured AWS Docker Containers for DDoS-for-Hire Service ShadowV2 Botnet Exploits Misconfigured AWS Docker Containers for DDoS-for-Hire Service The Hacker News
AryStinger Malware Targets Legacy Routers for Proxy Network AryStinger Malware Targets Legacy Routers for Proxy Network The Hacker News
Five New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Among Targets Five New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Among Targets The Hacker News
Google’s Quantum-Resistant HTTPS Initiative in Chrome Google’s Quantum-Resistant HTTPS Initiative in Chrome The Hacker News
ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages
  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages
  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark