Threat · curated 18 Sep 2026

PhantomRaven: LLM-generated Information Stealer for Bug Bounty Hunting

Coverage timeline

discovered crowdstrike.com primary 18 Sep 2026thehackernews.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

PhantomRaven demonstrates LLM-assisted malware authorship being used in a real, remediated npm supply-chain campaign, signaling how attackers weaponize generative AI to mass-produce info-stealers targeting developer credentials.

CrowdStrike Counter Adversary Operations assesses with high confidence that a financially motivated actor (self-described bug bounty hunter, monikers containing 'JPD') used an LLM to write PhantomRaven, a JavaScript information stealer distributed via more than 100 malicious npm packages that steals authentication tokens, CI/CD secrets, and GitHub credentials. The malware uses remote dynamic dependencies fetched from external servers to evade scanning, and CrowdStrike's LLM-authorship assessment is based on verbose comments, placeholder code, and statistical token-analysis patterns.