CrowdStrike says PhantomRaven was likely LLM-generated and spread through malicious npm packages that collect developer credentials and CI/CD secrets.