logo

PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers

ID: b0659653-3558-513b-8456-a9162f77bc68

STIX ID: report--b0659653-3558-513b-8456-a9162f77bc68

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-05-03

Date Updated: 2026-05-03

Author: Tom Abai

...
...

Mend documents PhantomRaven Wave 5: an active NPM supply-chain campaign using 33 malicious packages and a three-stage Remote Dynamic Dependency chain (Stage 0 npm package lure → Stage 1 redirect tarball → Stage 2 preinstall dropper → Stage 3 fileless payload) to silently harvest developer emails, CI/CD variables, credentials and environment data and exfiltrate it to pack.nppacks.com (also mirrored on hblnew.ecompk.com). The wave targets DeFi, cloud infra, AI/LLM, and JavaScript developers, remains live with C2 infrastructure and packages available on npm, and includes IoCs, hashes, and mitigation recommendations such as rotating credentials, blocking C2 domains/IPs, auditing HTTP dependencies, and using npm --ignore-scripts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.