logo

GhostClaw expands beyond npm: GitHub repositories and AI workflows deliver macOS infostealer

ID: 96090eca-0edc-56a2-860f-bd45e3c35fc1

STIX ID: report--96090eca-0edc-56a2-860f-bd45e3c35fc1

Feed Name: Jamf Blog

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-07-16

...
...

Jamf Threat Labs documents an active GhostClaw/GhostLoader campaign delivering a macOS credential-stealing infostealer via malicious GitHub repositories and AI "skill" installation workflows; attackers use staged repositories, curl|bash and SKILL.md installers to run an install.sh bootstrap that installs node, runs obfuscated setup.js to prompt for and validate credentials (via dscl and AppleScript), fetches an encrypted stage-two payload from trackpipe.dev, establishes persistence under npm-like paths, and uses postinstall.js to obscure activity; the report includes repository URLs, file SHA256s, campaign UUIDs, NODE_CHANNEL values, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.