
PhantomRaven npm Stealer Linked to LLM-Assisted Development by Financially Motivated Actor
A financially motivated threat actor has been linked to the development and distribution of a JavaScript-based information stealer named PhantomRaven via the npm package registry. Researchers assess with high confidence that the malware was likely written using a large language model (LLM), based on verbose comments, placeholder code, and statistical token-analysis patterns. The campaign poses a supply chain risk to npm users and downstream consumers.




