BlackTree Security · Infrastructure · Automation · AI

The Bug Bounty Hunter Allegedly Planted the Bugs First

A bug bounty is built on a bargain: find a weakness without harming the organisation, report it responsibly and receive recognition or payment. CrowdStrike says one actor may have reversed that order by distributing information-stealing npm packages, compromising companies and then using the access to identify findings for bounty submissions.

CrowdStrike calls the malware PhantomRaven. It assesses with high confidence that the JavaScript was generated with a large language model, based on token patterns, verbose comments, placeholders and inconsistent design choices. That is an analytic judgement, not proof supplied by the developer or a court finding.

The package fetched the real payload from outside npm

The typosquatted packages contained little obvious malicious code. They declared a dependency through an attacker-controlled HTTP URL. During installation, npm fetched a second package carrying the PhantomRaven preinstall script.

The stealer collected host, user, Git, npm and CI/CD information, including environment variables associated with GitHub Actions, GitLab CI, Jenkins and CircleCI. It sent the data to attacker infrastructure through HTTP requests. CrowdStrike says it responded to multiple incidents involving the malware.

The alleged business model abuses disclosure trust

CrowdStrike links the operator to public bug-bounty activity and says the actor contacted a potential victim about a compromised device. The actor attributed the incident to dependency confusion. CrowdStrike could not verify every claim, including an earlier assertion that a malicious package had produced remote code execution.

This distinction matters. A security company has made a high-confidence attribution based on multiple identifiers and incidents. That does not make every bounty submitted by the person fraudulent, nor does it establish criminal liability. Program operators should use the evidence to strengthen intake and conflict checks rather than treating all independent researchers as hostile.

Defend the package path and the reward process

  • Update npm. Newer releases restrict dependency install scripts unless explicitly approved.
  • Use a controlled registry. Proxy, allow-list and monitor package sources rather than permitting arbitrary URL dependencies.
  • Protect CI secrets. Limit environment variables and short-lived tokens to the job that needs them.
  • Correlate bounty submissions. Compare a report’s timing, infrastructure and indicators with recent endpoint and package incidents.
  • Keep safe-harbour boundaries explicit. Authorised testing must not include deploying malware or compromising unrelated systems.
  • Preserve fair review. Investigate evidence without publicly identifying a researcher beyond what is necessary and verified.

The strategic risk is not simply AI-written malware. It is a reward system that can be manipulated when the person creating the evidence is also the person asking to be paid for finding it.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *