On September 15, CrowdStrike published research on PhantomRaven, a JavaScript information stealer it says was distributed through malicious npm packages by a financially motivated bug bounty hunter.