Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Warm words on Canada’s EU ‘associate membership’ but no guarantees

    September 18, 2026

    Joining the dots between big AI

    September 18, 2026

    He Won the Nobel Prize for Protein Design. Now He Uses AI to Create Molecules Not Found in Nature

    September 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Warm words on Canada’s EU ‘associate membership’ but no guarantees
    • Joining the dots between big AI
    • He Won the Nobel Prize for Protein Design. Now He Uses AI to Create Molecules Not Found in Nature
    • Best Open-Source Agent Harnesses for Local LLMs in 2026
    • Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
    • SOL news: Solana speeds up blocks by 17%, but transaction capacity stays the same
    • NASA’s Moon orbiter finds a 728-foot crater that wasn’t there before
    • SOCAR spreads its wings into Africa’s oil & gas arena by coming aboard Eni’s project
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 18, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 18, 2026Malware / Cybercrime

    A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.

    “The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,” CrowdStrike’s Counter Adversary Operations said in an analysis published this week.

    PhantomRaven was first flagged by Koi Security and DCODX in late October 2025, calling attention to a slopsquatting and typosquatted campaign in which more than 100 malicious packages were uploaded to npm to steal authentication tokens, CI/CD secrets, and GitHub credentials from developers’ machines.

    The software supply chain attack used these packages as a cover to retrieve a remote dynamic dependency (RDD) from an external server so that the libraries themselves are not flagged by security tools.

    Once installed, the malware embedded in the remote dependency scans the developer environment for email addresses, gathers information about the CI/CD environment, collects a system fingerprint, including the public IP address, and transmits the results to an attacker-controlled server.

    Cybersecurity

    It’s also equipped to collect runtime details, current date and time, username and email addresses from Git/npm configurations, as well as CI/CD environment variables for GitHub Actions, GitLab CI, Jenkins, and CircleCI.

    The latest findings from CrowdStrike show that the threat actor has been active since November 2022 and claims to be a bug bounty hunter who has collected bounties from no less than nine entities across the technology, retail, and hospitality sectors.

    The cybersecurity company said it has not observed information stolen from the malware appearing on stealer log shops, indicating “the operator likely uses the information stealer solely to identify bug bounty opportunities.”

    At least two different npm user accounts maintained by the operator have been observed pushing npm packages containing PhantomRaven. Both npm accounts are no longer accessible as of writing.

    • jpdhellonpm1 – transform-jsbi-to-bigint
    • jpd15 – sort-imports-es6-autofix

    Some of the other online identities linked to the same operation include jpd12, jpd13, npmhell, npmpackagejpd, npmtestdharsh, jpdhackerone11, and packagedharsh.

    “In August 2025, the threat actor claimed to have discovered a remote code execution (RCE) vulnerability via a malicious npm package they published,” security researcher Maddie Stewart noted. “The threat actor explained that they had compromised the target machine and executed their preinstall script, which purportedly allowed them to achieve RCE.”

    Cybersecurity

    In addition, evidence has emerged that the threat actor attempted to push packages to the Python Package Index (PyPI) repository containing code for an information stealer that exhibits similarities with PhantomRaven.

    The likely use of a large language model (LLM) to generate the malware once again highlights how threat actors are increasingly adopting the technology in their operations, compressing the time and effort it takes to pull off such campaigns.

    “Most criminal actors […] rent commodity tools or operate their own proprietary malware; however, this threat actor has likely developed their proprietary PhantomRaven to compromise company assets and then used these compromises as leverage to claim rewards from reputable disclosure programs,” CrowdStrike said.

    Bounty Bug Build claimed hunter LLM npm PhantomRaven Stealer
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical Orkes Conductor Vulnerability Exploited in Attacks

    Microsoft fixes broken copy and paste for Excel 2016 users

    Crusoe raises $3.9B to build massive data centers and small modular ‘AI factories’

    RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

    Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

    Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Warm words on Canada’s EU ‘associate membership’ but no guarantees

    September 18, 2026

    Joining the dots between big AI

    September 18, 2026

    He Won the Nobel Prize for Protein Design. Now He Uses AI to Create Molecules Not Found in Nature

    September 18, 2026

    Best Open-Source Agent Harnesses for Local LLMs in 2026

    September 18, 2026
    Latest Posts

    ADNOC, SLB roll out AI-powered tool across over 120 rigs to enhance drilling ops

    August 4, 2026

    Mining threat persists in Raja Ampat, Indonesia’s ‘Amazon of the Seas’

    August 4, 2026

    Smoke Streams Across Eastern Washington

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Warm words on Canada’s EU ‘associate membership’ but no guarantees

    September 18, 2026

    Joining the dots between big AI

    September 18, 2026

    He Won the Nobel Prize for Protein Design. Now He Uses AI to Create Molecules Not Found in Nature

    September 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.