New Ghost Campaign Uses Fake npm Progress Bars to Phish Sudo Passwords
ID: 4bda86a2-7ded-5745-85ff-96b5fefcff49
STIX ID: report--4bda86a2-7ded-5745-85ff-96b5fefcff49
Feed Name: HackRead
Threat Score
Researchers identified the 'Ghost' campaign—malicious npm packages (published by handle 'mikilanjillo' and including names like react-state-optimizer-core and coinbase-desktop-sdk) that display fake install logs and progress bars to phish sudo passwords, deploy a RAT, and exfiltrate cryptocurrency wallets and sensitive files; multiple package versions and a subsequent similar package found by JFrog suggest broader supply-chain abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
