GhostClaw AI Assisted Malware Attacking macOS Users to Deploy Credential-Stealing Payloads
ID: 1db4c8cc-a93e-5e32-9f98-12f00cb5e480
STIX ID: report--1db4c8cc-a93e-5e32-9f98-12f00cb5e480
Feed Name: cybersecurityNews.com
Threat Score
GhostClaw is an active macOS-focused malware campaign spreading through malicious npm packages and impersonating GitHub repositories (including AI-agent-triggering SKILL.md files) to harvest credentials and install persistent JavaScript payloads; it leverages user social engineering, automated developer tooling, obfuscated installers, insecure downloads, and C2 retrieval (trackpipe.dev) to scale infections across developer ecosystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
