Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials
ID: da91f447-f66e-54e1-95d3-d821aefb3edd
STIX ID: report--da91f447-f66e-54e1-95d3-d821aefb3edd
Feed Name: The Hacker News
Researchers have identified a Ghost/GhostClaw campaign where malicious npm packages and impersonating GitHub repositories (published by actors such as 'mikilanjillo') use fake installation UIs and AI-assisted workflows to trick users into providing sudo credentials, then fetch a downloader via Telegram which deploys GhostLoader RAT and macOS stealers that harvest browser credentials, cryptocurrency wallets, SSH keys and cloud tokens; exfiltration and monetization are performed via partner-specific Telegram bots and a Binance Smart Chain smart contract.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
