Back to all news
Security

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

The Hacker News·September 18, 2026·1 min read
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

A financially motivated threat actor is linked to PhantomRaven, a JavaScript information stealer distributed via npm. Researchers assess with high confidence that the developer used a large language model to write the malware, based on verbose comments, placeholder code, and statistical token-analysis patterns. The stealer targets sensitive data from compromised systems.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store