GhostClaw AI Malware Targets macOS Users with Credential-Stealing Payloads
ID: 1631e211-901f-51ad-ac52-adbac80bead6
STIX ID: report--1631e211-901f-51ad-ac52-adbac80bead6
Feed Name: GBHackers
Threat Score
**Executive summary:** GhostClaw is a multi-stage macOS infostealer distributed via compromised or malicious GitHub repositories and AI-assisted “skill” installation workflows; it uses install.sh/setup.js flows to install Node.js, prompt for credentials (including via fake prompts and AppleScript), validate them, retrieve and decrypt a secondary payload from trackpipe.dev, and persist as a detached GhostLoader process while attempting to hide activity behind benign npm noise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
