logo

Fake npm Install Messages Conceal RAT Malware in New Open Source Supply Chain Attack

ID: ba658333-fe80-5105-b306-d1176537b9f5

STIX ID: report--ba658333-fe80-5105-b306-d1176537b9f5

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-26

Date Updated: 2026-05-11

Author: Mayura Kathir

...
...

ReversingLabs identified the "Ghost" campaign — malicious npm packages that present highly realistic fake npm install logs to lull developers into entering sudo credentials, then download, decrypt and execute a crypto‑stealing RAT. The report lists numerous package names and SHA1 hashes, describes multi‑stage retrieval via attacker‑controlled Telegram/web3 posts, and links the activity to GhostClaw/North Korea‑linked operations; defenders are advised to treat post‑install sudo prompts and post‑install external downloads as suspicious and to use automated supply‑chain security tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.