Threat · curated 18 Sep 2026
PhantomRaven: LLM-generated Information Stealer for Bug Bounty Hunting
First reported crowdstrike.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
PhantomRaven demonstrates LLM-assisted malware authorship being used in a real, remediated npm supply-chain campaign, signaling how attackers weaponize generative AI to mass-produce info-stealers targeting developer credentials.
CrowdStrike Counter Adversary Operations assesses with high confidence that a financially motivated actor (self-described bug bounty hunter, monikers containing 'JPD') used an LLM to write PhantomRaven, a JavaScript information stealer distributed via more than 100 malicious npm packages that steals authentication tokens, CI/CD secrets, and GitHub credentials. The malware uses remote dynamic dependencies fetched from external servers to evade scanning, and CrowdStrike's LLM-authorship assessment is based on verbose comments, placeholder code, and statistical token-analysis patterns.