GajAV - Malware Signature Update — PhantomRaven.JS.Stealer
These signatures detect the JavaScript payloads of PhantomRaven, an information-stealer documented by CrowdStrike in September 2026 and notable for being largely written by a large language model. It was distributed through the npm software registry by a financially-motivated actor (a self-described bug bounty hunter) who published packages with names imitating legitimate developer tools. The published packages look harmless — often just a trivial script — but they declare a hidden dependency fetched over a web link from the attacker's own server; when a developer installs the package, that server returns the actual stealer, which harvests system information, credentials, and software-development secrets such as CI/CD and repository tokens. These signatures identify the fetched stealer payloads by exact fingerprint.
If GajAV flags one of these files, treat it as a probable developer or build-system compromise: identify the affected machine (often a developer workstation or a continuous-integration runner), and because this stealer targets credentials and CI/CD and repository tokens, treat those as exposed — rotate npm, git, cloud, and CI secrets that the machine could reach, and review the associated repositories and pipelines for unauthorized use. Identify and remove the malicious npm package and its remote dependency, and audit the project's dependencies for other typosquatted packages.