Navegación

Es probable que el cazador de recompensas por errores (bug bounty hunter) utilizara un LLM para crear el malware de robo de datos PhantomRaven

fuente: https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.

"The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns," CrowdStrike's Counter Adversary Operations said in an analysis published this week.

PhantomRaven was first flagged by Koi Security and DCODX in late October 2025, calling attention to a slopsquatting and typosquatted campaign in which more than 100 malicious packages were uploaded to npm to steal authentication tokens, CI/CD secrets, and GitHub credentials from developers' machines.

The software supply chain attack used these packages as a cover to retrieve a remote dynamic dependency (RDD) from an external server so that the libraries themselves are not flagged by security tools.

Once installed, the malware embedded in the remote dependency scans the developer environment for email addresses, gathers information about the CI/CD environment, collects a system fingerprint, including the public IP address, and transmits the results to an attacker-controlled server.

Últimas noticias

21 DE AGOSTO, 2026

OpenAI ofrece cero retención de datos para modelos de IA de vanguardia con procesamiento de seguridad privada.

OpenAI ha anunciado la política de Cero Retención de Datos para los clientes elegibles de su API que utilizan sus modelos de IA de vanguardia, junto con un nuev...

Leer artículo →
21 DE AGOSTO, 2026

Citrix insta a los administradores a corregir las nuevas vulnerabilidades de NetScaler lo antes posible.

Citrix ha advertido a sus clientes que protejan inmediatamente sus sistemas contra dos vulnerabilidades que afectan a las soluciones de acceso remoto seguro Net...

Leer artículo →
21 DE AGOSTO, 2026

Cisco corrige nueve vulnerabilidades de Crosswork y Secure Workload, cinco de las cuales obtienen una puntuación CVSS de 10.0.

Cisco ha publicado una nueva ronda de actualizaciones de seguridad para las plataformas Crosswork y el software Secure Workload como parte de una revisión inter...

Leer artículo →