PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting
Summary
A financially motivated bug bounty hunter created PhantomRaven, a JavaScript-based information stealer (malware that collects sensitive data) distributed through npm, a popular platform where developers share code packages. The threat actor likely used an LLM to write the malware and deployed it via dependency-confusion attacks (tricking systems into downloading malicious packages instead of legitimate ones), though CrowdStrike's analysis suggests they use the stolen information only to identify bug bounty opportunities rather than selling it.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/
First tracked: September 16, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 85%