Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors phantomraven

Description

A fifth wave of the PhantomRaven NPM supply chain attack campaign has been discovered, utilizing 33 new malicious packages and fresh command-and-control infrastructure registered on March 10, 2026. The operation employs a sophisticated three-stage payload delivery mechanism using Remote Dynamic Dependency techniques to bypass static analysis. Malicious packages self-reference dependencies pointing to attacker-controlled servers at pack[.]nppacks[.]com, which deliver droppers that harvest developer credentials, system information, CI/CD tokens, GitHub repository names, and email addresses from Git configurations, NPM settings, and environment variables. The campaign specifically targets DeFi cryptocurrency developers, cloud infrastructure engineers working with Azure CDK, and AI application developers. All collected data is exfiltrated via POST requests to mozbra.php on the C2 server. Infrastructure analysis reveals connections to a legitimate Pakistani IT services company domain, suggesting potential accou...

Goals & Targeting

Targeted Sectors

Financial services

AI Analysis

· 1 week ago

Executive Summary

The PhantomRaven threat actor has launched a sophisticated fifth wave supply chain attack targeting DeFi, cloud infrastructure, and AI developers through malicious NPM packages. Their campaign utilizes dynamic dependency resolution to bypass detection and harvest sensitive credentials. The group's focus on financial services sectors indicates a potential interest in financial gain or espionage.

Goals & Targeting

PhantomRaven targets industries where intellectual property and financial gain are highly valuable, such as DeFi for cryptocurrency assets, cloud infrastructure for access to sensitive services, and AI for cutting-edge technology. Their strategic focus on developers suggests an aim to gather competitive intelligence or disrupt operations in these sectors.

Enhanced Description

PhantomRaven operates with high sophistication, employing a three-stage payload delivery mechanism via Remote Dynamic Dependency techniques. This method allows their malicious NPM packages to reference attacker-controlled dependencies, enabling credential harvesting and system information collection from infected machines. The data is then exfiltrated using POST requests to a C2 server at mozbra.php on pack.nppacks.com. Interestingly, the infrastructure has ties to a legitimate Pakistani IT services company, which may serve as a cover for their activities. This campaign underscores PhantomRaven's focus on targeting developers in critical sectors who handle sensitive financial and technological data. The attack vector through supply chains highlights their ability to penetrate deep into the software development lifecycle.

Key Capabilities

  • Supply chain compromise through NPM packages
  • Three-stage payload delivery mechanism
  • Credential harvesting from Git configurations
  • Data exfiltration via POST requests
  • Sophisticated dynamic dependency resolution

MITRE ATT&CK Tactics

Cyber Espionage
Initial Access
Defense Evasion
Execution
Exfiltration

ATT&CK Techniques

T1566.003
T1094
T1059
T1078

Software / Tooling

Custom malicious NPM packages
Droppers for credential harvesting
C2 infrastructure

Campaigns & Victims

PhantomRaven's campaign is ongoing, with active waves seen since March 2026. Their targets include developers across DeFi, cloud infrastructure, and AI, suggesting a deliberate focus on sectors with high financial stakes. Their use of legitimate infrastructure adds a layer of operational security, making detection challenging.

IOC Patterns

  • NPM package dependency exploitation: pack.nppacks.com
  • C2 communication via POST requests to mozbra.php
  • Staging infrastructure registration dates around March 10, 2026

Recommended Actions

  • Implement rigorous NPM package audits and monitoring
  • Enhance developer security awareness programs
  • Monitor for unusual outbound POST activities
  • Incorporate threat detection tools targeting supply chain attacks

Suggested Tags

APT
Supply-chain attack
Financial-Services
Cloud Infrastructure
AI Sector

Confidence Assessment

Confidence is high in the details regarding TTPs and targets due to comprehensive technical reporting. However, gaps remain in understanding their origin (e.g., state-sponsored vs. criminal), exact infection vectors beyond those reported, and long-term campaign objectives.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

14

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Supply Chain Attack
Backdoor / C2
APT
Supply-chain attack
Financial-Services
Cloud Infrastructure
AI Sector

Details

Type
Unknown
Confidence
55%
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.