Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
Summary
A threat actor likely used an LLM (large language model, an AI system that generates text) to build PhantomRaven, a malware stealer distributed through npm (a package registry where developers share code libraries). The malware uses typosquatting (creating packages with names similar to legitimate ones) and a remote dynamic dependency (RDD, code downloaded from an external server rather than included directly) to steal developer credentials and secrets from machines, with the attacker claiming to be a bug bounty hunter who reports vulnerabilities to collect rewards.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html
First tracked: September 18, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 75%