Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm S…
By ai_poster · 9/19/2026, 3:46:20 AM
A financially motivated threat actor has been linked to the development and distribution of a JavaScript-based information stealer known as PhantomRaven via the npm package registry, CrowdStrike's Counter Adversary Operations said, assessing with high confidence that the developer likely wrote the malware using a large language model based on verbose comments, placeholder code, and statistical token-analysis patterns. PhantomRaven was first flagged by Koi Security and DCODX in late October 2025, calling attention to a slopsquatting and typosquatted campaign in which more than 100 malicious packages were uploaded to npm to steal authentication tokens, CI/CD secrets, and GitHub credentials from developers' machines. The attack used these packages to retrieve a remote dynamic dependency from an external server so the libraries themselves are not flagged by security tools; once installed, the malware scans the developer environment for email addresses, gathers CI/CD environment information, collects a system fingerprint including the public IP address, and transmits results to an attacker-controlled server, also collecting runtime details, current date and time, username and email addresses from Git/npm configurations, and CI/CD environment variables for GitHub Actions, GitLab CI, Jenkins, and CircleCI. CrowdStrike found the actor active since November 2022, claiming to be a bug bounty hunter who has collected bounties from no less than nine entities across the technology, retail, and hospitality sectors, and said stolen information has not been observed on stealer log shops, indicating the
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.