AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

The Hacker News · article · Sep 18, 2026 · UTC

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"

Read original source ↗ Open in workspace

recordType
article
region
Global

Evidence & attribution

First collected: 2026-09-19T20:26:32.566Z. This is not the publication date.