A threat actor created the PhantomRaven information stealer using LLMs to facilitate fraudulent bug bounty submissions.

Reader brief
Through the Reader lens: A threat actor has been using malicious npm packages, known as PhantomRaven, to steal credentials and environment variables from developers. The attacker, who claims to be a bug bounty hunter, likely utilized large language models to write the malware. By compromising target machines, the actor aims to identify and claim bug bounties from various organizations rather than selling stolen data on log shops.
What to watch next
- Expansion of malicious activity into the PyPI repository
- Evolution of LLM-assisted malware development techniques by other threat actors
What was said1
Attributed, verbatim. Every quote is checked against the article it came from. One that does not match is not shown.
CrowdStrike
1 quote“The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,”
In the article
…A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. " The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns, " CrowdStrike's Counter Adversary Operations said in an analysis published this week. PhantomRaven was first flagged by Koi Security and DCODX in late October 2025, calling attention to a slopsquatting and typosquatted…
Sources1
- [1]The Hacker NewsneutralClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer