{"data":{"id":"a4f9d90b-d5a0-45cd-ae18-c09f1aba5ed2","title":"PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting","summary":"A financially motivated bug bounty hunter created PhantomRaven, a JavaScript-based information stealer (malware that collects sensitive data) distributed through npm, a popular platform where developers share code packages. The threat actor likely used an LLM to write the malware and deployed it via dependency-confusion attacks (tricking systems into downloading malicious packages instead of legitimate ones), though CrowdStrike's analysis suggests they use the stolen information only to identify bug bounty opportunities rather than selling it.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/","publishedAt":"2026-09-15T05:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain","data_extraction"],"issueType":"news","affectedPackages":null,"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["npm","PyPI","HuggingFace"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-15T05:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}