An advanced malware campaign targeting developers since August 2025 has deployed 126 malicious npm packages with over 86,000 total downloads. The attack, now identified as PhantomRaven , has harvested npm authentication tokens, GitHub credentials, and CI/CD pipeline secrets from developers around the world, using advanced evasion techniques that bypass most security tools.

Koi analysts discovered the campaign in October 2025 when their behavior monitoring system, Wings , noticed suspicious network activity during package installation processes. All malicious packages made external requests to the same suspicious domain, revealing a coordinated operation.
See also: PolarEdge botnet infected over 25,000 IoT devices
Research by Koi researchers revealed the following: 21 packages were detected and removed in August 2025, but the attackers adapted, successfully deploying 80 additional packages between September and October that completely evaded detection mechanisms.
The attacker's infrastructure shows an interesting contrast between advanced technical execution and surprisingly careless operational security. Consecutive email accounts from free providers, combined with obvious usernames like npmhell and npmpackagejpd, clearly point to a single threat actor.
Despite this operational negligence, the technical delivery mechanism represents a real innovation in supply chain attacks. The malicious packages looked completely innocent when examined on npmjs.com, presenting simple hello world scripts with seemingly zero dependencies.

This illusion was achieved through a technique involving Remote Dynamic Dependencies , where HTTP URLs act as dependency specifiers instead of traditional npm registry references. The malicious code was not in the package in question but in an invisible dependency retrieved from packages.storeartifact.com during installation, completely bypassing static analysis and dependency scanning tools
PhantomRaven: Remote Dynamic Dependencies deliver the malicious payload
Traditional npm dependencies refer to packages hosted on npmjs.com using standard version specifiers, such as “express”: “^4.18.0”. However, npm supports an obscure feature that allows HTTP URLs as dependency specifiers. When developers install packages containing these remote dependencies, npm automatically retrieves the external resources without any security or visibility.
See also: New attack combines Ghost SPNs and Kerberos reflection
Security scanners and automated analysis tools never follow these HTTP-based dependencies, treating the packets as having zero dependencies despite the hidden malicious payload. This creates a perfect blind spot where the examined packet appears completely safe while the actual malicious code resides on infrastructure controlled by the attacker.
The technique is made even more dangerous because each installation retrieves the dependency from the attacker's server, allowing for dynamic payload delivery based on the target environment. Once the invisible dependency reaches the victim's system, the automatic execution of npm ensures immediate activation of the malware.

The malicious package.json contains a preinstall script that is automatically executed without any prompt or warning to the user. This script is executed regardless of how deeply the malicious package is embedded in the dependency tree, meaning that developers who install seemingly legitimate packages can inadvertently trigger the execution of PhantomRaven via transitive dependencies.
After successful installation, PhantomRaven systematically collects email addresses from environment variables, .gitconfig files, .npmrc settings, and author fields in package.json.
The malware then targets CI/CD credentials, including GitHub Actions tokens, GitLab CI credentials, Jenkins authentication, CircleCI tokens, and npm publishing tokens.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: 10 malicious npm packages with auto-execution capability
This is followed by full system fingerprinting, collecting public IP addresses, hostnames, operating system details, Node.js versions, and network configurations to profile victims' environments and identify high-value corporate networks versus individual developer machines.
