security2 publishers
The PhantomRaven operator turned stolen CI/CD secrets into bug bounty payouts, CrowdStrike says
CrowdStrike says the npm stealer's author has been active since November 2022, claims bounties from at least nine companies, and that none of the stolen logs have turned up for sale. It assesses with high confidence that an LLM wrote the code.
Reality
- Evidence60
- Adoption55
- Hype gap+25
- Incentives70
- Confidence58