PhantomRaven Malware Has Targeted CI/CD Pipelines

A new JavaScript-based information stealer distributed via npm packages is harvesting critical environment variables.

Updated on Oct. 10, 2026 in Cybersecurity

Isometric editorial illustration of a shipping container resting on a server rack with copper circuit paths, representing software supply chain security.
CrowdStrike identified PhantomRaven, a new malware strain distributed through npm packages that harvests critical environment variables from development pipelines. AI Illustration. Upload story photo >

Live Poll

Do you worry that using open-source software libraries makes your personal or professional data less secure?

CrowdStrike has identified PhantomRaven, a new JavaScript-based malware strain designed to extract system credentials and CI/CD environment variables. Threat actors are actively distributing the malicious code through compromised npm packages.

Why it matters

The campaign highlights an evolving threat vector where financially motivated actors leverage software supply chain platforms to infiltrate sensitive development environments. By targeting CI/CD configurations, attackers gain access to secure infrastructure credentials.

PhantomRaven functions as a JavaScript-based info-stealer that scans for and captures CI/CD environment variables. Evidence suggests the malicious code was generated using a large language model.

The players

CrowdStrike

A cybersecurity firm specializing in endpoint protection, cloud workload security, and threat intelligence.

The details

The attackers operate by masquerading as bug bounty hunters to distribute malicious npm packages—a repository service for JavaScript software libraries. Once installed, the malware runs on the victim's machine to siphon sensitive environment variables and credentials used within Continuous Integration and Continuous Deployment (CI/CD) pipelines. CI/CD pipelines are the automated tools that developers use to build, test, and deploy code updates to production environments.

Timeline

  1. October 10, 2026: Official identification and analysis reported.

The Tech Race

The rise of PhantomRaven follows an established trend of threat actors utilizing the npm registry to distribute malicious code, illustrating a continued focus on software supply chain exploitation. This campaign shifts the frontier of these attacks by integrating LLM-generated code to automate the creation of effective, obfuscated payloads.

Developers and IT teams should audit their CI/CD pipeline dependencies for any unauthorized or suspicious npm packages. Organizations should also prioritize credential rotation for any systems where suspicious package activity was detected.

The takeaway

The deployment of LLM-generated malware via legitimate repositories signals an increase in the sophistication of supply chain attacks. Security teams should monitor for anomalous behavior within automated build environments to detect early stages of credential harvesting.

Further reading

Learn more about the latest Cybersecurity developments affecting global software infrastructure.

Source note: This article includes information reported by The CyberWire.

Live Poll

Do you worry that using open-source software libraries makes your personal or professional data less secure?