PhantomRaven Malware Has Targeted CI/CD Pipelines
A new JavaScript-based information stealer distributed via npm packages is harvesting critical environment variables.
Updated on Oct. 10, 2026 in Cybersecurity

Live Poll
Do you worry that using open-source software libraries makes your personal or professional data less secure?
CrowdStrike has identified PhantomRaven, a new JavaScript-based malware strain designed to extract system credentials and CI/CD environment variables. Threat actors are actively distributing the malicious code through compromised npm packages.
Why it matters
The campaign highlights an evolving threat vector where financially motivated actors leverage software supply chain platforms to infiltrate sensitive development environments. By targeting CI/CD configurations, attackers gain access to secure infrastructure credentials.
PhantomRaven functions as a JavaScript-based info-stealer that scans for and captures CI/CD environment variables. Evidence suggests the malicious code was generated using a large language model.
The players
CrowdStrike
A cybersecurity firm specializing in endpoint protection, cloud workload security, and threat intelligence.
The details
The attackers operate by masquerading as bug bounty hunters to distribute malicious npm packages—a repository service for JavaScript software libraries. Once installed, the malware runs on the victim's machine to siphon sensitive environment variables and credentials used within Continuous Integration and Continuous Deployment (CI/CD) pipelines. CI/CD pipelines are the automated tools that developers use to build, test, and deploy code updates to production environments.
Timeline
October 10, 2026: Official identification and analysis reported.
The Tech Race
The rise of PhantomRaven follows an established trend of threat actors utilizing the npm registry to distribute malicious code, illustrating a continued focus on software supply chain exploitation. This campaign shifts the frontier of these attacks by integrating LLM-generated code to automate the creation of effective, obfuscated payloads.
Developers and IT teams should audit their CI/CD pipeline dependencies for any unauthorized or suspicious npm packages. Organizations should also prioritize credential rotation for any systems where suspicious package activity was detected.
The takeaway
The deployment of LLM-generated malware via legitimate repositories signals an increase in the sophistication of supply chain attacks. Security teams should monitor for anomalous behavior within automated build environments to detect early stages of credential harvesting.
Further reading
Learn more about the latest Cybersecurity developments affecting global software infrastructure.
Source note: This article includes information reported by The CyberWire.
Live Poll
Do you worry that using open-source software libraries makes your personal or professional data less secure?






