> Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
[DATE: 18/09/2026 09:18]
[LANGUAGE: EN]
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.
"The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"