Zero Day Room
Live
Threats

PhantomRaven npm Stealer Likely Built Using LLM

A threat actor posing as a bug bounty hunter used an LLM to create the PhantomRaven info-stealer, distributing it via over 100 malicious npm packages to

A threat actor posing as a bug bounty hunter used an LLM to create the PhantomRaven info-stealer, distributing it via...

A financially motivated threat actor has been distributing a JavaScript-based information stealer called PhantomRaven through the npm registry. CrowdStrike's Counter Adversary Operations assesses with high confidence that the malware was likely written using a large language model (LLM).

The security firm based its assessment on verbose comments, placeholder code, and statistical token-analysis patterns found within the malware's code. The campaign, first identified by Koi Security and DCODX in late October 2025, involved uploading more than 100 malicious packages using slopsquatting and typosquatting techniques.

Attack Methodology and Stealer Capabilities

The packages served as a vehicle to fetch a remote dynamic dependency from an external server, a technique designed to evade detection by security tools. Once installed on a developer's machine, the PhantomRaven malware activates.

It conducts a comprehensive scan of the development environment. The stealer hunts for authentication tokens, CI/CD secrets, and GitHub credentials. It also collects email addresses, system fingerprint data including the public IP address, and runtime details.

Specific targets include username and email addresses from Git and npm configurations. The malware is also equipped to harvest CI/CD environment variables from several popular platforms.

All stolen data is transmitted to a server controlled by the attacker.

The Actor's Profile and Claims

CrowdStrike's investigation traces the threat actor's activity back to November 2022. The individual claims to be a bug bounty hunter who has received bounties from at least nine companies across the technology, retail, and hospitality sectors.

Interestingly, the cybersecurity company said it has not seen information stolen by PhantomRaven appear on stealer log shops. This suggests "the operator likely uses the information stealer solely to identify bug bounty opportunities."

The actor maintained at least two npm accounts to push packages containing the stealer, both of which are now inaccessible. The accounts and associated packages included jpdhellonpm1, which published transform-jsbi-to-bigint, and jpd15, which published sort-imports-es6-autofix.

Other online aliases linked to the same operation include jpd12, jpd13, npmhell, npmpackagejpd, npmtestdharsh, jpdhackerone11, and packagedharsh.

Expanding Tactics and LLM Adoption

The actor's methods extend beyond simple credential theft. "In August 2025, the threat actor claimed to have discovered a remote code execution (RCE) vulnerability via a malicious npm package they published," security researcher Maddie Stewart noted. The actor explained they compromised a target machine and executed a preinstall script to achieve RCE.

There is also evidence the threat actor attempted to upload similar information-stealing code to the Python Package Index (PyPI) repository. The likely use of an LLM for malware development shows a growing trend. Threat actors are adopting the technology to compress the time and effort required for such campaigns.

CrowdStrike highlighted this shift in tactics. Most criminal actors rent commodity tools or use their own proprietary malware. This actor, however, likely developed PhantomRaven themselves to compromise company assets. They then used these compromises as leverage to claim rewards from reputable disclosure programs.

Related coverage

More from Threats