logo

Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign

ID: 3e34d303-96e2-57e5-a430-fe5f0fc5278b

STIX ID: report--3e34d303-96e2-57e5-a430-fe5f0fc5278b

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A software supply-chain campaign dubbed “Ghost” (and a related cluster “GhostClaw”) is distributing a remote access trojan through malicious npm packages that present fake install logs and prompt for sudo passwords to stealthily obtain root credentials; the RAT steals cryptocurrency wallets, harvests data, and provides remote access, with final payloads and keys retrieved from Telegram channels and obfuscated web3 posts. The report lists affected package names, versions, and SHA1 hashes as IoCs and recommends verifying package authors, avoiding entering sudo during installs, and enforcing dependency review and automated scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.