PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting CrowdStrike Counter Adversary Operations identified a threat actor behind PhantomRaven, an LLM-generated information stealer distributed through typosquatted npm packages that use remote dynamic dependency links to the domain npm[.]jpartifacts[.]com for command and control, according to a CrowdStrike report. The actor, linked to GitHub and PyPI accounts and the email jpdtester01@gmail[.]com, was accused by a PyPI organization member of building an information stealer after submitting a GitHub issue in February 2025 asking why their code failed to upload; the main project was removed but associated Python files remain accessible. npm released a new version in June 2026 that blocks preinstall scripts in dependency packages unless developers explicitly allow them, with npm version 12 or later warning developers when such scripts are blocked. The usernames jpdhellonpm1 and jpd15 are similar to usernames that industry sources associate with PhantomRaven deployments using malicious npm packages. These usernames include jpd12 , jpd13 , npmhell , npmpackagejpd , npmtestdharsh , jpdhackerone11 , and packagedharsh .