logo

GhostLoader Malware Spreads Through Fake OpenClaw npm Package

ID: c997edf1-a741-5bbd-b1be-c5143f27fcd6

STIX ID: report--c997edf1-a741-5bbd-b1be-c5143f27fcd6

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2026-03-10

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

This report describes GhostLoader, a sophisticated information-stealer and RAT distributed through a malicious npm package posing as an OpenClaw installer; the fake installer performs a staged infection, prompts for system credentials (to unlock keychains and browser encryption), exfiltrates browser sessions, credentials, crypto wallets, SSH/cloud keys and developer secrets, and establishes persistence. The article highlights live browser cloning, global installation to PATH, multiple persistence techniques, available IoCs and mitigation guidance for developers to reduce exposure to npm supply-chain attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.