Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
AI-summarised brief · reviewed before publication
A financially motivated threat actor linked to the npm registry released the JavaScript-based stealer PhantomRaven, targeting developers’ authentication tokens and CI/CD secrets. CrowdStrike’s analysis suggests the malware was likely written with a large language model, based on verbose comments and token‑analysis patterns. The actor, who claims bug‑bounty credentials, distributed over 100 malicious packages via slopsquatting and typosquatting, embedding a remote dynamic dependency that harvests system fingerprints, email addresses, and CI/CD environment variables. No stolen data has appeared on stealer log shops, implying the operator uses the tool to identify bounty opportunities.
💡 Why It Matters
- · The case demonstrates how AI‑generated code can accelerate sophisticated supply‑chain attacks, turning open‑source ecosystems into vectors for targeted credential theft and exploitation.