Learn
active
PhantomRaven npm Stealer Likely Developed with LLM Assistance
- Engineer — Learn: LLM-assisted malware development lowering the barrier for supply-chain attacks on npm is worth noting for security posture, but the summary names no specific packages or versions to audit — monitor threat intel feeds for IOCs before taking action.
- SOC/IR — Learn: No IOCs, package names, or ATT&CK-mapped TTPs are provided, so no detection or hunt is actionable now; file the LLM-written malware pattern as context for future npm-related alert triage.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.