GhostLoader Malware Spreads Through Fake OpenClaw npm Package
ID: c997edf1-a741-5bbd-b1be-c5143f27fcd6
STIX ID: report--c997edf1-a741-5bbd-b1be-c5143f27fcd6
Feed Name: SOCRadar Blog
This report describes GhostLoader, a sophisticated information-stealer and RAT distributed through a malicious npm package posing as an OpenClaw installer; the fake installer performs a staged infection, prompts for system credentials (to unlock keychains and browser encryption), exfiltrates browser sessions, credentials, crypto wallets, SSH/cloud keys and developer secrets, and establishes persistence. The article highlights live browser cloning, global installation to PATH, multiple persistence techniques, available IoCs and mitigation guidance for developers to reduce exposure to npm supply-chain attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
