Ghost campaign remote access trojan payload
Malware Activity
Summary
Hide ▲
Show ▼
A malicious npm payload tied to the Ghost campaign began in early February and used fake installation logs to hide a remote access trojan (RAT) that could steal crypto wallets and sensitive data. The malware matters because it also accepted commands from a command-and-control (C2) server, giving attackers ongoing control over infected systems. The delivery chain combined downloader functionality, sudo password capture, and local execution after decryption.
Related Happenings
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Deps credential stealer in hijacked Arch AUR builds
Malware Activity
H score3
First: 12.06.2026 22:24
Last: 12.06.2026 22:24
Sources 1
About this happening:
Atomic Arch is a malware activity that hijacked more than 400 Arch User Repository (AUR) packages on or after June 11 and rewrote their build scripts to run npm...
Deps credential stealer in hijacked Arch AUR builds
Malware ActivityAbout this happening: Atomic Arch is a malware activity that hijacked more than 400 Arch User Repository (AUR) packages on or after June 11 and rewrote their build scripts to run npm...
Malware-Slop malicious npm file-theft campaign
Campaign
H score39
First: 27.05.2026 18:44
Last: 27.05.2026 18:44
Sources 1
About this happening:
Malware-Slop is distributing mouse5212-super-formatter, a malicious npm package that steals local files from Anthropic's Claude workspace directory /mnt/user-dat...
Malware-Slop malicious npm file-theft campaign
CampaignAbout this happening: Malware-Slop is distributing mouse5212-super-formatter, a malicious npm package that steals local files from Anthropic's Claude workspace directory /mnt/user-dat...
Timeline
-
24.03.2026 16:30 2 articles · 3mo ago
ReversingLabs identifies Ghost campaign in npm
Initial DisclosureReversingLabs identified a malicious npm supply-chain campaign dubbed the Ghost campaign, which began in early February and used fake installation logs and downloader packages to hide malware activity while attempting to capture sudo passwords for later execution of a remote access trojan that could steal crypto wallets and sensitive data.
Show sources
- New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide Malware — www.infosecurity-magazine.com — 24.03.2026 16:30
- New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide Malware — www.infosecurity-magazine.com — 24.03.2026 16:30