A threat actor distributed a JavaScript information stealer called PhantomRaven through the npm package registry, likely using an LLM to generate the malware code based on linguistic and structural analysis.
Summary is Secursion's own; full text lives at the source. Attribution preserved.