Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Threat intel: Bug bounty hunter by day, malware developer by night

Security researchers have uncovered a highly active bug bounty hunter who deploys an LLM-coded infostealer to find their next payday.

Thu, 17 Sep 2026
Threat intel: Bug bounty hunter by day, malware developer by night

Bug bounty hunters are generally considered white knights of the hacking scene, diligently searching for vulnerabilities in applications that may otherwise remain unfound, and seeking payment in return.

These bounties can be anywhere up to US$40,000 for serious issues, and while many pocket the proceeds, some donate these payments to charities.

Regardless, bug bounty hunters have become an essential part of the cyber security ecosystem. But there are exceptions, and the big brains at CrowdStrike found exactly that – a bounty hunter who deploys their own malware to identify payout opportunities.

 
 

“CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software,” Maddie Stewart, a member of the team, said in a 15 September blog post.

“The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns.”

The hacker – and let’s be honest, that’s what they are – behind PhantomRaven contacted one of their victims in late 2025, claiming to have identified a device compromised by a dependency-confusion attack that had deployed the malware via malicious npm packages.

CrowdStrike noted several identifiers that linked PhantomRaven to the unnamed bounty hunter, who claims to have been actively informing companies of vulnerabilities since 2022 via several well-known bug bounty platforms, including HackerOne, Bugcrowd, and Intigriti. The contact email used by the hunter matches a three-letter string in the usernames behind the maintainer of a pair of npm packages linked to the malware.

“The threat actor discussed in this post likely operates both monikers; this assessment is made with high confidence, as both PhantomRaven packages contain files with the threat actor’s name and initials in the description and author fields, respectively, and both usernames include the string JPD from the initial contact email,” CrowdStrike said.

CrowdStrike has also observed similarities in timing between PhantomRaven campaigns and the bounty hunter’s own vulnerability claims.

The malware itself is distributed via typosquatted npm packages with simple scripts, but it also calls upon an HTTP URL, which returns the malicious package. PhantomRaven is capable of collecting system information, runtime data, user IDs, and environment variables for GitHub Actions.

Despite this data collection capability, CrowdStrike has not observed any PhantomRaven logs for sale in the usual hacking communities, “further indicating that PhantomRaven’s operator likely uses the information stealer solely to identify bug bounty opportunities”.

You can read CrowdStrike’s full analysis of the threat actor and their malware here.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: