logo

GhostClaw AI Malware Targets macOS Users with Credential-Stealing Payloads

ID: 1631e211-901f-51ad-ac52-adbac80bead6

STIX ID: report--1631e211-901f-51ad-ac52-adbac80bead6

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive summary:** GhostClaw is a multi-stage macOS infostealer distributed via compromised or malicious GitHub repositories and AI-assisted “skill” installation workflows; it uses install.sh/setup.js flows to install Node.js, prompt for credentials (including via fake prompts and AppleScript), validate them, retrieve and decrypt a secondary payload from trackpipe.dev, and persist as a detached GhostLoader process while attempting to hide activity behind benign npm noise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.