THREATOPS
THREAT OPSThreat News › Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

lowthehackernewsPublished 2026-09-18

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.

"The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"

MITRE ATT&CK techniques

Original source: https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html