Threat Actor Exploits LLM to Craft PhantomRaven npm Stealer A financially motivated threat actor used a large language model to craft PhantomRaven, a JavaScript information stealer whose code shows telltale signs of AI involvement including verbose comments and placeholder code, according to the report. The malware's LLM-assisted development marks a case of generative AI being used to build credential-stealing code. Meet PhantomRaven, a sneaky JavaScript information stealer crafted by a financially motivated actor - and likely created with the help of a large language model, a cutting-edge AI tool. The surprising twist? The malware's code reveals telltale signs of AI involvement, including verbose comments and placeholder code.