Exclusive: AI-written malware helped a hacker cash in on bug bounty programs
CrowdStrike researchers report that a financially motivated hacker used a large language model to help write malware for attacks that leveraged bug bounty programs. The malware, dubbed PhantomRaven, was delivered through malicious open-source npm packages. After developers installed the packages, PhantomRaven executed on their systems to collect information, including credentials and other sensitive development data. CrowdStrike assesses the hacker used it to compromise company assets and hunt for vulnerabilities, then used those findings to submit bugs to legitimate programs for payouts. The attacker also posted about collecting bounties from at least nine companies, though the report says it’s unclear which were actually compromised. CrowdStrike said it has not seen stolen data from the campaign sold on criminal marketplaces.






