PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers
ID: b0659653-3558-513b-8456-a9162f77bc68
STIX ID: report--b0659653-3558-513b-8456-a9162f77bc68
Feed Name: Security Boulevard
Mend documents PhantomRaven Wave 5: an active NPM supply-chain campaign using 33 malicious packages and a three-stage Remote Dynamic Dependency chain (Stage 0 npm package lure → Stage 1 redirect tarball → Stage 2 preinstall dropper → Stage 3 fileless payload) to silently harvest developer emails, CI/CD variables, credentials and environment data and exfiltrate it to pack.nppacks.com (also mirrored on hblnew.ecompk.com). The wave targets DeFi, cloud infra, AI/LLM, and JavaScript developers, remains live with C2 infrastructure and packages available on npm, and includes IoCs, hashes, and mitigation recommendations such as rotating credentials, blocking C2 domains/IPs, auditing HTTP dependencies, and using npm --ignore-scripts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
