A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.”The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,”
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html
![]()

