Fake npm Install Messages Conceal RAT Malware in New Open Source Supply Chain Attack
ID: ba658333-fe80-5105-b306-d1176537b9f5
STIX ID: report--ba658333-fe80-5105-b306-d1176537b9f5
Feed Name: GBHackers
ReversingLabs identified the "Ghost" campaign — malicious npm packages that present highly realistic fake npm install logs to lull developers into entering sudo credentials, then download, decrypt and execute a crypto‑stealing RAT. The report lists numerous package names and SHA1 hashes, describes multi‑stage retrieval via attacker‑controlled Telegram/web3 posts, and links the activity to GhostClaw/North Korea‑linked operations; defenders are advised to treat post‑install sudo prompts and post‑install external downloads as suspicious and to use automated supply‑chain security tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
