Exclusive: AI-written malware helped a hacker cash in on bug bounty programs
CrowdStrike has found a hacker who cracked the ultimate business model: write the malware with AI, push it out through published open-source npm packages, let it compromise companies, then collect bug bounty money for the flaws you helped create. He found the bugs, filed the reports, and got paid — genuinely paid, the article insists, through legitimate bounty programmes. The malware is called PhantomRaven, which sounds less like a supply-chain attack and more like a mid-tier Marvel villain. Axios got the research first — the 'shared first with Axios' credit being, as ever, the actual product being launched here.
Note the phrase 'legitimate bug bounty payments', because that is where the caper stops being a crime story and becomes a business plan. Bug bounty programmes exist so a stranger will politely point out the hole in your wall; this gentleman built the hole, shipped it via npm, then invoiced you for the survey and banked the fee. AI-written means the code costs him nothing to produce, an open-source package means delivery is free, and a bounty programme means the exit is cash — that is not a hack, that is vertical integration. Somewhere, a board is being told this is an AI-era talent pipeline.
What the report withholds is the interesting part: no name for the hacker, no count of the companies compromised, no figure for the bounties collected, no list of the packages that carried PhantomRaven into some developer's build at two in the morning. So we are left with the shape of the thing — malicious code, machine-written, moving through the very open-source registries every startup's deployment depends on — plus the reassurance that a security vendor saw it first. Marvellous. The follow-up CrowdStrike exclusive will presumably feature a hacker who charges a subscription for the privilege of being robbed monthly.