A financially motivated threat actor, who works as a bug bounty hunter, developed and distributed the JavaScript-based information stealer PhantomRaven via npm. The actor likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns. The threat actor deployed PhantomRaven by contacting potential victim organizations and claiming to have identified compromised devices due to dependency-confusion attacks that used malicious npm packages.
The actor attributed the compromise to a dependency-confusion attack that used malicious npm packages to deploy PhantomRaven. They used remote dynamic dependency (RDD) links to the domain for command and control (C2). Infection occurred via email, where the threat actor contacted potential victims claiming to have identified compromised devices.[/subscribe_to_unlock_form]
A financially motivated threat actor, who works as a bug bounty hunter, developed and distributed the JavaScript-based information stealer PhantomRaven via npm. The actor likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns. The threat actor deployed PhantomRaven by contacting potential victim organizations and claiming to have identified compromised devices due to dependency-confusion attacks that used malicious npm packages.
The actor attributed the compromise to a dependency-confusion attack that used malicious npm packages to deploy PhantomRaven. They used remote dynamic dependency (RDD) links to the domain for command and control (C2). Infection occurred via email, where the threat actor contacted potential victims claiming to have identified compromised devices.[emaillocker id="1283"]
The threat actor has been active and has collected bounties from at least nine entities across various sectors. They operate under multiple usernames, including jpdhellonpm1 and jpd15, which are similar to industry sources associated with PhantomRaven deployments using malicious npm packages. The threat actor uses the information stealer solely to identify bug bounty opportunities.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1195 | Supply Chain Compromise | - |
| Initial access | T1195.002 | Supply Chain Compromise | Compromise Software Supply Chain |
| Execution | T1059.007 | Command and Scripting Interpreter | JavaScript |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Credential access | T1552.001 | Unsecured Credentials | Credentials In Files |
| Discovery | T1082 | System Information Discovery | - |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Discovery | E1083 | File and Directory Discovery |
| Discovery | E1082 | System Information Discovery |
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
The following reports contain further technical details:
[/emaillocker]