PhantomRaven npm Stealer Linked to LLM-Generated Malware by Alleged Bug Bounty Hunter
A threat actor is linked to developing the PhantomRaven npm stealer using a large language model (LLM), exploiting npm packages to steal developer credentials and CI/CD secrets through supply chain attacks. The malware uses remote dependencies to evade detection while collecting system and environment data for bug bounty opportunities.
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.
"The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"
*** END OF TRANSMISSION ***