Exclusive: AI-written malware helped a hacker cash in on bug bounty programs
CrowdStrike says a hacker used AI-written malware to compromise companies and search for software bugs, which he then submitted for payments through legitimate bug bounty programmes. The research was shared first with Axios. According to the article, the malware is named PhantomRaven, and it was distributed through malicious open-source npm packages that the hacker published. The article's headline describes the malware as 'AI-written' and says the hacker cashed in on bug bounty programmes.
The article describes the sequence as follows: the hacker published malicious packages on npm; those packages delivered the PhantomRaven malware; the malware was used to compromise companies; and the bugs he located in the course of that activity were submitted to bug bounty programmes as legitimate reports. It describes the resulting payments as legitimate bug bounty payments. The report does not state how many companies were compromised, how many packages were published, what the malware did once installed, or the total value of the payments received.
The article presents the case as an example of AI-written malicious code moving through open-source software distribution. It does not name the hacker, the companies affected, or the bug bounty programmes that paid out. CrowdStrike's research was shared with Axios before publication, and the article does not say whether the activity was reported to law enforcement or whether the packages remain available. It also does not state which AI model or tool was used to write the malware.