Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-17 Β· updated: 2026-09-17 Β· tags: [incident, global] Β· confidence: high Β· severity: low Β· affected_sectors: [global] Β· au_impact: true

CrowdStrike's Counter Adversary Operations has profiled PhantomRaven, a JavaScript information stealer distributed through npm by an operator who works as a bug bounty hunter β€” and who, CrowdStrike assesses with high confidence, likely wrote the malware with a large language model, on the evidence of verbose comments, placeholder code and statistical token-analysis patterns. The operator is attributed to two npm accounts, jpdhellonpm1 and jpd15, publishing packages named transform-jsbi-to-bigint and sort-imports-es6-autofix; both packages carry files containing the threat actor's name and initials in their description and author fields, both usernames include the string "JPD" that appeared in the address used to contact a potential victim, and industry sources associate further usernames β€” jpd12, jpd13, npmhell, npmpackagejpd, jpdhackerone11 β€” with PhantomRaven deployments. In November 2025 the operator contacted a potential victim organisation claiming to have identified a compromised device and attributing it to a dependency-confusion attack using malicious npm packages to deploy PhantomRaven, an approach that reads as an extortion or credibility play built on their own intrusion tooling. The operator has been publicly active as a bug bounty hunter since November 2022 and, by their own account, has collected bounties from at least nine entities across technology, retail and hospitality through Bugcrowd, Intigriti, YesWeHack, HackenProof and HackerOne. CrowdStrike has not observed PhantomRaven logs for sale on log shops, which supports its assessment that the stealer is used to find submission-worthy findings rather than to sell access β€” a materially different economic model from the crimeware market. CrowdStrike Falcon Complete responded to and remediated multiple incidents involving the stealer.

Attribute Detail
Sector Global (Macro)
Date 2026-09-17
Source CrowdStrike
Reliability Tier 1