logo

GhostClaw AI Assisted Malware Attacking macOS Users to Deploy Credential-Stealing Payloads

ID: 1db4c8cc-a93e-5e32-9f98-12f00cb5e480

STIX ID: report--1db4c8cc-a93e-5e32-9f98-12f00cb5e480

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

GhostClaw is an active macOS-focused malware campaign spreading through malicious npm packages and impersonating GitHub repositories (including AI-agent-triggering SKILL.md files) to harvest credentials and install persistent JavaScript payloads; it leverages user social engineering, automated developer tooling, obfuscated installers, insecure downloads, and C2 retrieval (trackpipe.dev) to scale infections across developer ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.