The investigation into PhantomRaven reveals a disturbing development in software supply-chain attacks: an actor claiming to be a legitimate bug bounty hunter has been linked to the distribution of malicious npm packages designed to steal sensitive information from developer environments. According to CrowdStrike's analysis, the financially motivated actor likely used a large language model to help develop the JavaScript-based information stealer.

Researchers identified characteristics such as unusually verbose comments, placeholder code and statistical patterns consistent with AI-assisted development. While these indicators support CrowdStrike's assessment, they do not conclusively identify the AI system involved or establish that the entire malware-development process was automated. 
PhantomRaven was initially exposed in October 2025 when researchers identified a campaign involving more than 100 malicious packages uploaded to the npm registry. The packages used techniques including typosquatting, which relies on developers mistyping legitimate package names, and slopsquatting, which exploits plausible but nonexistent package names that may be suggested by AI coding assistants. These techniques take advantage of the enormous trust placed in open-source package repositories, where developers routinely install third-party dependencies to accelerate application development. A seemingly harmless package can become an entry point into a developer workstation or automated build environment when its installation causes attacker-controlled code to execute.

The campaign's use of remote dynamic dependencies is particularly important because it separates the apparently ordinary npm package from the code responsible for stealing information. Instead of embedding the entire malicious payload directly within the published package, the attacker used the package as a mechanism to retrieve additional code from an external server. This creates a detection challenge because the package initially inspected by a developer or automated scanning tool may not contain all the functionality that will eventually execute. The behaviour of the installed software can therefore depend on content controlled by an external server, potentially changing after the package has been published or reviewed. 

Once executed, PhantomRaven searches the developer's environment for valuable information, including email addresses, Git and npm configuration details, system fingerprints and public IP addresses. It also examines CI/CD-related information and environment variables associated with platforms such as GitHub Actions, GitLab CI, Jenkins and CircleCI. The collected information is transmitted to attacker-controlled infrastructure. These targets are significant because developer environments frequently contain credentials that provide access to source-code repositories, automated build systems, deployment infrastructure and cloud services. A successful compromise can therefore extend beyond one workstation into the broader software-development environment. 

The targeting of CI/CD secrets creates a particularly serious supply-chain risk. Modern development pipelines often use environment variables and access tokens to authenticate with repositories, package registries, cloud infrastructure and deployment services. If an attacker obtains these credentials, the potential consequences depend on their privileges and validity. Stolen tokens may allow unauthorised access to private repositories, modification of build configurations or interaction with deployment systems. A malicious package installed as a development dependency can consequently expose infrastructure and information that would normally require privileged access, illustrating why the security of software dependencies is inseparable from the security of the software-delivery process. 

The unusual aspect of the PhantomRaven investigation is the actor's claimed connection to legitimate bug bounty activity. CrowdStrike linked the operation to an individual who claims to have collected rewards from at least nine organisations across the technology, retail and hospitality sectors. Researchers also identified an August 2025 statement in which the actor claimed to have discovered a remote-code-execution vulnerability by publishing a malicious npm package and causing its installation script to execute on a target machine. These findings raise serious questions about the boundary between authorised vulnerability research and deliberately compromising systems to manufacture or discover reportable security issues. 

Legitimate bug bounty programmes operate within defined scopes and rules of engagement. Researchers are authorised to test specified systems using permitted techniques and to disclose vulnerabilities responsibly. Publishing credential-stealing malware, obtaining unauthorised access or extracting secrets from developer environments falls outside ordinary responsible-disclosure practices unless a programme has explicitly authorised a narrowly defined test. A vulnerability identified after an unauthorised compromise cannot automatically be considered legitimate research simply because the individual subsequently submits a bug report. The method used to obtain access matters as much as the vulnerability eventually reported. 

CrowdStrike's investigation suggests that the actor may have used compromised company assets as leverage to pursue bug bounty rewards. Researchers reported that they had not observed PhantomRaven's stolen information appearing on stealer-log marketplaces, leading them to assess that the information may have been collected primarily to identify bug bounty opportunities. This is an important distinction, but it should not be interpreted as evidence that the activity caused no harm. Unauthorised collection of authentication tokens, development secrets and internal information constitutes a security incident regardless of whether the data is subsequently sold, publicly disclosed or used for another form of financial gain. 

The reported use of AI introduces another significant dimension. Large language models can assist with writing code, documenting functions, debugging errors and adapting existing scripts. These capabilities are valuable for legitimate software development, but they can also reduce the effort required to create malicious tooling. In the PhantomRaven case, CrowdStrike's high-confidence assessment suggests that AI assistance may have helped the actor develop a proprietary information stealer rather than relying entirely on purchased or rented malware. However, the evidence does not establish that AI independently planned the campaign, selected targets or conducted the intrusion. The more immediate concern is that AI can accelerate parts of malware development while established attack techniques continue to provide the actual route into victim environments. 

The investigation also identified at least two npm accounts used to distribute PhantomRaven packages, both of which were no longer accessible when the report was published. Researchers additionally found indications that the actor attempted to publish similar credential-stealing functionality through the Python Package Index. This suggests that the threat was not necessarily limited to a single programming language or package ecosystem. Organisations should therefore avoid treating malicious dependencies as an npm-only problem and establish consistent software supply-chain controls across all package managers used in development and production. 

For enterprise security teams, the incident reinforces the need to inspect what dependencies do during installation, not merely what they claim to provide. Package names, descriptions and apparent functionality are insufficient indicators of trustworthiness. Security reviews should consider publisher reputation, package history, unexpected installation scripts, external code retrieval and unusual attempts to access environment variables or developer configuration files. Organisations should also maintain dependency inventories and use controlled package repositories where appropriate, reducing the likelihood that an unreviewed package can be introduced directly into a sensitive build pipeline. 

Credential protection is equally important. Development and CI/CD environments should use narrowly scoped credentials with limited lifetimes wherever possible. Secrets should be stored in dedicated management systems rather than embedded in source code or exposed broadly as persistent environment variables. Build jobs should receive only the credentials required for their specific task, and untrusted dependencies should not be installed in environments possessing unrestricted access to production deployment credentials. These measures cannot prevent every malicious package from executing, but they can substantially reduce the consequences of a compromised dependency. 

Network security and data loss prevention can provide additional visibility into this attack pattern. A newly installed package that unexpectedly connects to an unfamiliar external server, retrieves executable code or transmits configuration information may be exhibiting behaviour inconsistent with its stated purpose. Monitoring outbound connections from developer workstations and build systems can help identify suspicious dependency activity, particularly when combined with endpoint process telemetry and knowledge of approved package registries. Contextual monitoring is especially valuable because the same protocols used for legitimate dependency downloads and software updates can also be used to retrieve malicious payloads and exfiltrate secrets. 

Organisations that discover a PhantomRaven package in their environment should treat the incident as a potential credential compromise rather than simply deleting the package and resuming development. The investigation should determine when the package was installed, which processes executed its code, what environment variables and configuration files were accessible, and whether suspicious outbound connections occurred. Potentially exposed tokens should be revoked or rotated according to their privileges and the evidence obtained. Relevant source-code repositories, CI/CD workflows and deployment activity should also be reviewed for unauthorised changes. Removing the dependency closes one entry point, but it does not invalidate credentials that may already have been stolen. 

The broader lesson is that open-source package repositories are part of an organisation's security perimeter. Every external dependency introduces code developed and maintained outside the organisation's direct control, while installation scripts and dynamic dependencies can create execution paths that are not immediately visible through ordinary source-code review. AI-assisted development adds another layer to the problem by making it easier to generate plausible package names, create convincing package descriptions and potentially develop malicious code with less manual effort. Effective defence requires combining dependency governance, credential isolation, controlled build environments, network monitoring and rapid incident response. 

Ultimately, PhantomRaven demonstrates how an attacker can exploit the trust placed in open-source software and potentially manipulate the legitimate vulnerability-disclosure ecosystem for financial gain. The campaign combined malicious npm packages, remotely retrieved payloads, developer credential theft and an alleged bug bounty motive, while researchers assessed that AI likely assisted in developing the malware. The immediate security priority is to protect development environments and ensure that a compromised dependency cannot automatically obtain access to the organisation's most sensitive credentials or deployment infrastructure.


A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"

Source: Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer via The Hacker News — published 18 Sep 2026.