Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
Researchers linked a financially motivated hacker to the development and distribution of the JavaScript stealer PhantomRaven via the npm registry. With high confidence, the malware was written using a large language model, indicated by verbose comments, stub code, and statistical token analysis.
- PhantomRaven stealer distributed via packages in npm registry
- Analysts with high confidence believe code was written by LLM
- Signs: detailed comments, stubs, and token patterns
Read next
Security