logo

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

ID: da91f447-f66e-54e1-95d3-d821aefb3edd

STIX ID: report--da91f447-f66e-54e1-95d3-d821aefb3edd

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers have identified a Ghost/GhostClaw campaign where malicious npm packages and impersonating GitHub repositories (published by actors such as 'mikilanjillo') use fake installation UIs and AI-assisted workflows to trick users into providing sudo credentials, then fetch a downloader via Telegram which deploys GhostLoader RAT and macOS stealers that harvest browser credentials, cryptocurrency wallets, SSH keys and cloud tokens; exfiltration and monetization are performed via partner-specific Telegram bots and a Binance Smart Chain smart contract.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.