{"data":{"id":"c5bca5ee-f9de-408a-b5ea-c43fc4d1728a","title":"Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer","summary":"A threat actor likely used an LLM (large language model, an AI system that generates text) to build PhantomRaven, a malware stealer distributed through npm (a package registry where developers share code libraries). The malware uses typosquatting (creating packages with names similar to legitimate ones) and a remote dynamic dependency (RDD, code downloaded from an external server rather than included directly) to steal developer credentials and secrets from machines, with the attacker claiming to be a bug bounty hunter who reports vulnerabilities to collect rewards.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html","publishedAt":"2026-09-18T09:18:03.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["npm","PyPI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-18T09:18:03.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}