Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
CrowdStrike ties the PhantomRaven npm infostealer, active since 2022, to a self-described bug bounty hunter who likely wrote it with an LLM.
CrowdStrike's Counter Adversary Operations assessed with high confidence that the PhantomRaven developer, active since November 2022 and claiming bounties from nine organizations, used an LLM to write the malware, citing verbose comments, placeholder code, and token-analysis patterns. First flagged by Koi Security and DCODX in late October 2025, the campaign uploaded more than 100 typosquatted and slopsquatted npm packages that retrieve a remote dynamic dependency to evade scanners, then harvest auth tokens, CI/CD secrets for GitHub Actions, GitLab CI, Jenkins, and CircleCI, Git/npm identities, and system fingerprints. npm accounts jpdhellonpm1 and jpd15 pushed the packages, and similar stealer code was also pushed to PyPI; stolen data has not appeared in stealer log shops, suggesting it is used to find bug bounty targets.