A financially motivated threat actor has been linked to the creation and distribution of a JavaScript-based information stealer called PhantomRaven through the npm package registry This article explores malware threat actor. . The developer likely used a large language model (LLM) to craft the malware, as assessed by CrowdStrike's Counter Adversary Operations, based on verbose comments, placeholder code, and statistical token-analysis patterns.

PhantomRaven was initially flagged by Koi Security and DCODX in late October 2025, raising awareness of a slopsquatting and typosquatted campaign involving the upload of more than 100 malicious packages to npm.

Once installed, the malware embedded in the remote dependency scans the developer's environment for email addresses, gathers information about the CI/CD environment, collects a system fingerprint, including the public IP address, and transmits the results to an attacker-controlled server. The latest findings from CrowdStrike indicate that the threat actor has been active since November 2022 and claims to be a bug bounty hunter who has collected bounties from nine entities across the technology, retail, and hospitality sectors. "Most criminal actors rent commodity tools or operate their own proprietary malware, but this threat actor has reportedly developed their own PhantomRaven, a tool to compromise company assets and then leverage these breaches to claim rewards from reputable disclosure programs," CrowdStrike stated.