New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide Malware
ID: 9e23b356-8373-5075-ae16-0595199b18a7
STIX ID: report--9e23b356-8373-5075-ae16-0595199b18a7
Feed Name: Infosecurity Magazine (News)
A new malicious npm campaign dubbed the "Ghost campaign" was discovered delivering downloader packages that display fake installation logs to trick users into providing sudo credentials; those credentials are then used to decrypt and execute a RAT that steals crypto wallets and sensitive data. Researchers observed multiple similar packages, external payload delivery (Telegram and hidden web3 content), and recommend verifying package authors, monitoring install scripts, using automated scanners, and avoiding entering sudo passwords during installs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
