Cybersecurity Research

PhantomRaven: An AI-Written Info Stealer Hidden in npm Packages, Used to Hunt Bug Bounties

CrowdStrike · 15 Sept 2026
Key Takeaway Australian businesses using npm or other open-source package repositories should audit their dependencies regularly and restrict automatic installation of unverified third-party packages to reduce exposure to malicious code.

CrowdStrike's Counter Adversary Operations team has identified a financially motivated actor who built and distributed a JavaScript-based information stealer called PhantomRaven through npm, the popular open-source package platform used by developers worldwide. Analysts assess with high confidence that the malware was written using a large language model, based on tell-tale signs like overly detailed comments, placeholder code, and unusual token patterns typical of AI-generated software.

Unlike most malware operators, this actor appears to be a self-styled bug bounty hunter, active since November 2022, who has collected rewards from at least nine organisations across technology, retail, and hospitality sectors via legitimate platforms including Bugcrowd, Intigriti, YesWeHack, HackenProof, and HackerOne. In one case, the actor contacted a potential victim directly, claiming to have found a compromised device caused by a dependency-confusion attack involving malicious npm packages. CrowdStrike has found no evidence that stolen PhantomRaven data is being sold on underground log shops, suggesting the actor's goal is identifying bug bounty opportunities rather than profiting from data theft.

CrowdStrike's Falcon Complete team responded to and remediated several incidents involving PhantomRaven, tracing it to two npm packages, transform-jsbi-to-bigint and sort-imports-es6-autofix, published under accounts linked to the same threat actor through shared naming patterns and initials embedded in the code.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from CrowdStrike. We link back to every original so you can read it yourself.