The Return of PhantomRaven: Detecting Three New Waves of npm Supply Chain Attacks
Blog post from Endor Labs
The PhantomRaven campaign, a significant npm supply chain attack, targeted over 126 packages with more than 86,000 downloads, using a method called Remote Dynamic Dependencies (RDD) to covertly download malicious payloads during standard npm installations. Initially identified by Koi Security in October 2025, the campaign involved multiple waves, with attackers rotating infrastructure, modifying operational details, and utilizing disposable npm accounts to evade detection. Despite a security researcher's claim that the data collection was intended to highlight vulnerabilities in CI/CD infrastructure, the packages collected extensive information without transparency, casting doubt on their legitimacy as research artifacts. Subsequent updates saw a significant reduction in the data-harvesting code and a shift in the campaign's operational details, yet highlighted the risks associated with URL dependencies, which allow package authors to change payloads without updating the npm registry. The campaign remains partially active, with some packages still available and command-and-control servers operational, underscoring the need for clearer community guidelines on acceptable practices in software supply chain vulnerability research.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 1,488 | 268 | 99 | +7% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.