Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI-Assisted Malware Targets npm Users with PhantomRaven

AI-Assisted Malware Targets npm Users with PhantomRaven

Posted on September 18, 2026 By CWS

A financially driven cybercriminal group has been linked to the creation and dissemination of PhantomRaven, a JavaScript-based malware. This malicious software is being distributed through the npm package registry, targeting developers to extract sensitive information.

Development and Distribution of PhantomRaven

According to CrowdStrike’s Counter Adversary Operations, the malware was likely crafted using a large language model (LLM). This conclusion is based on detailed analysis, including verbose comments, placeholder code, and statistical patterns within the code. PhantomRaven was initially identified by Koi Security and DCODX in late October 2025, highlighting a campaign involving over 100 malicious npm packages designed to steal authentication tokens, CI/CD secrets, and GitHub credentials.

These packages act as a conduit to fetch a remote dynamic dependency (RDD) from an external server, making it difficult for security tools to detect the libraries as threats. Once operational, the malware scans developer environments for email addresses, collects CI/CD environment data, and gathers system fingerprints, including public IP addresses, all of which are sent to a server controlled by the attacker.

Impact on Software Supply Chain

The malware is also capable of obtaining runtime details, dates, times, and user information from Git/npm configurations, along with CI/CD environment variables for platforms like GitHub Actions, GitLab CI, Jenkins, and CircleCI. CrowdStrike’s recent findings reveal that the threat actor has been active since November 2022, posing as a bug bounty hunter and claiming to have earned rewards from at least nine different organizations in sectors such as technology, retail, and hospitality.

No stolen data from this malware has been found on stealer log markets, suggesting that the attacker uses the stolen information solely to find bug bounty opportunities. Two npm accounts associated with the attacker, used to distribute PhantomRaven, are now inaccessible.

Expanding Operations and Future Threats

Additional online aliases linked to this operation include jpd12, jpd13, npmhell, and others. In August 2025, the threat actor reportedly discovered a remote code execution (RCE) vulnerability through a malicious npm package they released. This was achieved by compromising a target machine and executing a preinstall script to enable RCE.

Furthermore, there is evidence that the threat actor attempted to extend their operations to the Python Package Index (PyPI) repository with similar malware. The use of a large language model to develop PhantomRaven emphasizes the growing trend of cybercriminals leveraging AI technologies to streamline their malicious activities.

CrowdStrike noted that while many cybercriminals rent or develop their own proprietary malware, this particular actor has likely created PhantomRaven to infiltrate company systems and use these breaches to claim rewards from legitimate disclosure programs.

The Hacker News Tags:AI malware, bug bounty, CrowdStrike, Cybercrime, Cybersecurity, JavaScript malware, LLM, npm security, PhantomRaven, supply chain attack

Post navigation

Previous Post: Critical Flaws in BIND DNS Servers Threaten Security
Next Post: Critical Vulnerabilities Patched by Top Cybersecurity Firms

Related Posts

Scanning Activity on Palo Alto Networks Portals Jump 500% in One Day Scanning Activity on Palo Alto Networks Portals Jump 500% in One Day The Hacker News
Google Eliminates AI Workflows Over GitHub Security Flaw Google Eliminates AI Workflows Over GitHub Security Flaw The Hacker News
WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability The Hacker News
New TETRA Radio Encryption Flaws Expose Law Enforcement Communications New TETRA Radio Encryption Flaws Expose Law Enforcement Communications The Hacker News
Google Integrates Rust DNS Parser in Pixel 10 for Security Google Integrates Rust DNS Parser in Pixel 10 for Security The Hacker News
Gunra Ransomware Targets Global Infrastructure via Exploited Flaws Gunra Ransomware Targets Global Infrastructure via Exploited Flaws The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service
  • CISA Recommends Cyber Decoys to Detect Hackers
  • Critical Vulnerabilities Patched by Top Cybersecurity Firms
  • AI-Assisted Malware Targets npm Users with PhantomRaven

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service
  • CISA Recommends Cyber Decoys to Detect Hackers
  • Critical Vulnerabilities Patched by Top Cybersecurity Firms
  • AI-Assisted Malware Targets npm Users with PhantomRaven

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark