{"id":2969,"date":"2026-09-18T09:31:56","date_gmt":"2026-09-18T09:31:56","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2969"},"modified":"2026-09-18T09:31:56","modified_gmt":"2026-09-18T09:31:56","slug":"claimed-bug-bounty-hunter-likely-used-llm-to-build-phantomraven-npm-stealer","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2969","title":{"rendered":"Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 18, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Cybercrime<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjyW8DcUYeyW1LOG-Gc3uqyV8_5rO4iwyEIM6FbRFwuvilvbfC7RSTjueJ4lEELpGvXX-22zzWuNCusN2qdODymiKNOQSz_8f1Q4u59bH7HCEZFT5PVsyBjj2NhWtlYiwvhXzXbwG_n3P_DCloZvMdajsc93hvqbJo6HCJy5wjNevUyN46ODFo7AlYsj499\/s1700-nu-rw-lo-l85-e365\/npm-cicd.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as <strong>PhantomRaven<\/strong> via the npm package registry.<\/p>\n<p>\u00abThe developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,\u00bb CrowdStrike&#8217;s Counter Adversary Operations <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting\/\" target=\"_blank\">said<\/a> in an analysis published this week.<\/p>\n<p>PhantomRaven was first flagged by Koi Security and DCODX in late October 2025, calling attention to a slopsquatting and typosquatted campaign in which more than 100 malicious packages were uploaded to npm to steal authentication tokens, CI\/CD secrets, and GitHub credentials from developers&#8217; machines.<\/p>\n<p>The software supply chain attack used these packages as a cover to retrieve a remote dynamic dependency (RDD) from an external server so that the libraries themselves are not flagged by security tools.<\/p>\n<p>Once installed, the malware embedded in the remote dependency scans the developer environment for email addresses, gathers information about the CI\/CD environment, collects a system fingerprint, including the public IP address, and transmits the results to an attacker-controlled server.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It&#8217;s also equipped to collect runtime details, current date and time, username and email addresses from Git\/npm configurations, as well as CI\/CD environment variables for GitHub Actions, GitLab CI, Jenkins, and CircleCI.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The latest findings from CrowdStrike show that the threat actor has been active since November 2022 and claims to be a bug bounty hunter who has collected bounties from no less than nine entities across the technology, retail, and hospitality sectors.<\/p>\n<p>The cybersecurity company said it has not observed information stolen from the malware appearing on stealer log shops, indicating \u00abthe operator likely uses the information stealer solely to identify bug bounty opportunities.\u00bb<\/p>\n<p>At least two different npm user accounts maintained by the operator have been observed pushing npm packages containing PhantomRaven. Both npm accounts are no longer accessible as of writing.<\/p>\n<ul>\n<li>jpdhellonpm1 &#8211; transform-jsbi-to-bigint<\/li>\n<li>jpd15 &#8211; sort-imports-es6-autofix<\/li>\n<\/ul>\n<p>Some of the other online identities linked to the same operation include jpd12, jpd13, npmhell, npmpackagejpd, npmtestdharsh, jpdhackerone11, and packagedharsh.<\/p>\n<p>\u00abIn August 2025, the threat actor claimed to have discovered a remote code execution (RCE) vulnerability via a malicious npm package they published,\u00bb security researcher Maddie Stewart noted. \u00abThe threat actor explained that they had compromised the target machine and executed their preinstall script, which purportedly allowed them to achieve RCE.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/event-security-need\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJkE4t8oCql1wmWVt687J1yD7WnYRqvIpcsUwFSVUO-0HpxZWMCxLmeYwBlz38-C0KD-R6f9Pg0swgPTQuBsNXck_Kl3iKWNSQtyMcDNUSZGhiBd_XFu6U1SQi5LhuW-FHg00iT3CbRCUgMoCwhZevwxp8-9gwM2wZVVtGVO8Z2NbZ5EjVmI2dH4adnSAk\/s728-nu-rw-lo-l85-e365\/Shai-Hulud-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>In addition, evidence has emerged that the threat actor attempted to push packages to the Python Package Index (PyPI) repository containing code for an information stealer that exhibits similarities with PhantomRaven.<\/p>\n<p>The likely use of a large language model (LLM) to generate the malware once again highlights how threat actors are increasingly adopting the technology in their operations, compressing the time and effort it takes to pull off such campaigns.<\/p>\n<p>\u00abMost criminal actors [&#8230;] rent commodity tools or operate their own proprietary malware; however, this threat actor has likely developed their proprietary PhantomRaven to compromise company assets and then used these compromises as leverage to claim rewards from reputable disclosure programs,\u00bb CrowdStrike said.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 18, 2026Malware \/ Cybercrime A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2970,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2675,610,1972,1736,3456,140,39,3457,478],"class_list":["post-2969","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-bounty","tag-bug","tag-build","tag-claimed","tag-hunter","tag-llm","tag-npm","tag-phantomraven","tag-stealer"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2969","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2969"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2969\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2970"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2969"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2969"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2969"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}