logo

Fake install logs in npm packages load RAT

ID: 0b76e2fd-fb13-502d-a52e-7785f8f2440e

STIX ID: report--0b76e2fd-fb13-502d-a52e-7785f8f2440e

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-30

Author: Lucija Valentić

...
...

ReversingLabs discovered a malicious npm ‘Ghost campaign’ that publishes several packages which mimic normal installs with fake console output to phish for sudo passwords; the harvested credentials are used to run a downloaded, encrypted final-stage RAT that steals crypto wallets and sensitive data. The campaign uses Telegram (and in one case a web3 post) to host final payload URLs and decryption keys, includes development/test artifacts in some packages, and comes with collected IOCs and detection guidance via Spectra Assure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.