fuente: https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.
"The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns," CrowdStrike's Counter Adversary Operations said in an analysis published this week.
PhantomRaven was first flagged by Koi Security and DCODX in late October 2025, calling attention to a slopsquatting and typosquatted campaign in which more than 100 malicious packages were uploaded to npm to steal authentication tokens, CI/CD secrets, and GitHub credentials from developers' machines.
The software supply chain attack used these packages as a cover to retrieve a remote dynamic dependency (RDD) from an external server so that the libraries themselves are not flagged by security tools.
Once installed, the malware embedded in the remote dependency scans the developer environment for email addresses, gathers information about the CI/CD environment, collects a system fingerprint, including the public IP address, and transmits the results to an attacker-controlled server.
El Servicio Federal de Seguridad de la Federación Rusa (FSB) anunció el miércoles que acusó al fundador de Telegram, Pavel Durov, de presuntamente facilitar act...
Leer artículo →Microsoft ha publicado la actualización acumulativa de vista previa KB5101684 para Windows 11 24H2 y 25H2, que incluye 42 correcciones de errores y mejoras adic...
Leer artículo →Las versiones beta de dos paquetes npm del espacio de nombres @joyfill se han visto comprometidas para distribuir un troyano de acceso remoto (RAT) asociado a l...
Leer artículo →