Skip to content
Threat Feed
high advisory

PhantomRaven Information Stealer

A bug bounty hunter is leveraging LLM-generated JavaScript information stealers distributed via malicious npm packages to identify vulnerabilities for bounty submissions.

CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who utilizes LLM-generated JavaScript (JS) code to create the PhantomRaven information stealer. Active since November 2022, the actor operates as a bug bounty hunter, using the malware to identify security weaknesses in target environments for submission to bug bounty programs rather than selling logs on illicit marketplaces.

The actor distributes the malware via dependency-confusion attacks on the npm registry, hosting malicious packages such as 'transform-jsbi-to-bigint' and 'sort-imports-es6-autofix'. Analysis of the code reveals characteristics highly indicative of LLM generation, including verbose comments, placeholder code, and specific token-analysis patterns. The actor frequently contacts organizations to disclose vulnerabilities, using the claim of a successful compromise as leverage for bounty payouts.

Attack Chain

  1. The attacker publishes typosquatted or malicious packages (e.g., 'transform-jsbi-to-bigint') to the public npm registry.
  2. A developer or automated build system installs the malicious dependency into their development or production environment.
  3. The package's 'preinstall' script executes automatically upon installation via the npm package manager.
  4. The script executes a secondary payload that initiates a connection to attacker-controlled infrastructure, such as 'npm.jpartifacts.com'.
  5. PhantomRaven collects system information and potentially sensitive environment data from the infected host.
  6. The data is exfiltrated to the C2 infrastructure to facilitate the actor's vulnerability discovery process.
  7. The attacker contacts the victim, claiming to have achieved RCE or unauthorized access to justify a bug bounty submission.

Impact

The use of PhantomRaven allows the threat actor to gain unauthorized access to target environments. While the primary goal observed is vulnerability discovery for bug bounty payouts, the capability of the information stealer poses a significant risk to the confidentiality and integrity of victim networks, potentially exposing environment variables, configuration files, and proprietary source code.

Recommendation

  • Block the C2 domains 'npm.jpartifacts.com', 'packages.storeartifact.com', 'registry.storageartifact.com', and 'packages.storageartifact.com' at the DNS resolver and proxy levels.
  • Implement package vetting processes to detect and prevent the installation of typosquatted or untrusted npm/PyPI dependencies.
  • Use software composition analysis (SCA) tools to audit project dependencies for suspicious 'preinstall' scripts and unexpected network requests during build-time.
  • Monitor internal network egress for unusual HTTP/HTTPS connections originating from build servers or developer workstations to the identified C2 infrastructure.

Immediate actions

Block listed C2 domains and IP addresses

SOC 24h

Mitigations

Review and audit npm/PyPI dependencies for project build environments

immediate IT Operations

Supply Chain Compromise

Indicators of compromise

4

domain

3

hash_sha256

1

ip

TypeValue
domainnpm.jpartifacts.com
domainpackages.storeartifact.com
domainregistry.storageartifact.com
domainpackages.storageartifact.com
ip54.173.15.59
hash_sha256c31831d47fcbf52ff1f4e61838611916a4276d005a564e69946d5dac04235eed
hash_sha25695a7dcc6de46826b22c43bee7fc550f3b5e2e6cbc5f33b0c241faf523641cf63
hash_sha256db3fe46df0a65fe9f8c99d2e11126a032a72e9814e354ce017448ce088a01e02