Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
thehackernews.com Sep 18, 2026

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

AI-summarised brief · reviewed before publication

A financially motivated threat actor linked to the npm registry released the JavaScript-based stealer PhantomRaven, targeting developers’ authentication tokens and CI/CD secrets. CrowdStrike’s analysis suggests the malware was likely written with a large language model, based on verbose comments and token‑analysis patterns. The actor, who claims bug‑bounty credentials, distributed over 100 malicious packages via slopsquatting and typosquatting, embedding a remote dynamic dependency that harvests system fingerprints, email addresses, and CI/CD environment variables. No stolen data has appeared on stealer log shops, implying the operator uses the tool to identify bounty opportunities.

💡 Why It Matters

  • · The case demonstrates how AI‑generated code can accelerate sophisticated supply‑chain attacks, turning open‑source ecosystems into vectors for targeted credential theft and exploitation.