VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_1963d1923e71383cfdc7ff37dd1f76ca

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

Published Sep 18, 2026

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.

"The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"

Affected AI Products

large language model llm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.