CrowdStrike has identified a hacker going by the alias PhantomRaven, who posed as a bug bounty hunter while distributing AI-generated malware. Disguised as legit npm libraries, PhantomRaven uploaded packages to npm repositories that, once installed, would deploy a stealer on the victim’s device. The malware collected system data and other info, which the attacker then used to access corporate environments and hunt for vulnerabilities—ultimately to claim bug bounty rewards.
How the Attack Worked
The operator hid malicious code inside npm packages that looked totally normal to developers. Once installed, these libraries activated a stealer that harvested system info. Researchers say the tool itself was pretty basic, but it let the attacker prep access to company networks.
Who Was Behind It
According to CrowdStrike, the campaign was run by someone using the handle PhantomRaven. Their goal was to gain entry into organizations’ systems under the guise of vulnerability research and bug hunting.
Why This Matters
This case shows how open-source package repositories can be used to deliver malware. Masking malicious code as legit libraries makes it way easier for attackers to breach corporate infrastructure.
