Ai-powered cyberattacks exploit open-source software for bug bounties
A hacker exploited AI-generated malware distributed through open-source software to compromise companies and submit bugs for legitimate bug bounty payments, according to CrowdStrike research shared with Axios. The malware, known as PhantomRaven, was embedded in malicious npm packages.
CrowdStrike researchers have high confidence that the financially motivated attacker used a large language model to craft the malware, leveraging comments, placeholder code, and token patterns found in the script.
Adam Meyers, CrowdStrike's senior vice president of counter adversary operations, noted that participating in bug bounty programs helped the hacker establish credibility within the broader hacker community. The attack highlights how AI is reducing technical barriers for cybercrime, enabling less-sophisticated actors to scale their operations.
While the malware used in this campaign is relatively simple and relies on well-known supply-chain techniques, the case underscores the growing adoption of AI by malicious actors.