New PhantomRaven NPM Attack Hits Developers: 88 Malicious Packages Found Stealing Data
Mar 11, 2026 // 23:27 - Niko Dunn


The PhantomRaven threat actor group has launched a sophisticated supply chain attack targeting the NPM ecosystem, deploying 88 malicious packages designed to exfiltrate sensitive data from developer environments.

The Attack Mechanism

Researchers from Phylum and Checkmarx discovered that the campaign uses a combination of typosquatting and dependency confusion to trick developers into installing the malicious code.

  • Targeted Data: Once installed, the packages execute a multi-stage payload that scans for SSH keys, cloud provider credentials (.aws, .azure), and environment variables containing API tokens.
  • Execution: The malicious scripts are often embedded in the preinstall or postinstall hooks of the package.json file, ensuring the attack triggers automatically during a standard npm install.
  • Stealth Tactics: PhantomRaven uses GitHub Pages and hijacked Netlify subdomains as command-and-control (C2) servers to blend in with legitimate developer traffic.

Impact and Scope

The 88 identified packages mimic popular utilities like react-router-dom, lodash, and chalk.

  • Developer Profiles: The attack specifically targets developers working in fintech and blockchain sectors, as evidenced by the specific search for local wallet files and crypto-related configuration data.
  • Geographic Focus: While the attack is global, a high concentration of downloads was traced back to IP addresses in North America and Western Europe.

How to Protect Your Environment

To mitigate the risk of PhantomRaven and similar supply chain threats:

  • Lockfiles: Always use package-lock.json or yarn.lock to ensure sub-dependencies aren’t swapped for malicious versions.
  • Audit Tools: Run npm audit regularly and use specialized tools like Socket or Snyk to detect behavioral anomalies in dependencies.
  • Namespace Verification: Double-check the scope (e.g., @babel/core vs babel-core) before installing new packages.

#attack  #data  #developers’  #found  #hits  #malicious  #new  #news  #npm  #packages  #phantomraven  #stealing   —   News