GhostLoader staged npm install payload activity
Malware Activity
Summary
Hide ▲
Show ▼
GhostLoader is now being delivered through staged npm install scripts, turning routine package installation into a route for data theft and cryptocurrency wallet targeting. The chain uses fake install logs and a bogus permissions error to push developers into revealing a sudo/root password. After that step, the malware retrieves a downloader that connects to C2 infrastructure and fetches the final payload. The result is a remote access trojan that can harvest data, focus on wallets, and wait for further instructions.
Related Happenings
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware Activity
H score30
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware ActivityAbout this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
CrashStealer macOS information stealer activity
Malware Activity
H score10
First: 13.07.2026 20:36
Last: 13.07.2026 20:36
Sources 1
About this happening:
CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
CrashStealer macOS information stealer activity
Malware ActivityAbout this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
QuimaRAT cross-platform Java MaaS remote access trojan
Malware Activity
H score29
First: 06.07.2026 11:13
Last: 06.07.2026 11:13
Sources 1
About this happening:
A new QuimaRAT MaaS offering expands cross-platform malware risk by packaging a modular Java-based RAT for Windows, Linux, and macOS. The activity matters because...
QuimaRAT cross-platform Java MaaS remote access trojan
Malware ActivityAbout this happening: A new QuimaRAT MaaS offering expands cross-platform malware risk by packaging a modular Java-based RAT for Windows, Linux, and macOS. The activity matters because...
Timeline
-
24.03.2026 14:00 2 articles · 3mo ago
ReversingLabs identifies malicious npm packages published by mikilanjillo
Initial DisclosureSecurity researchers identify seven malicious npm packages published by mikilanjillo, including react-performance-suite, react-state-optimizer-core, react-fast-utilsa, ai-fast-auto-trader, pkgnewfefame1, carbon-mac-copy-cloner, and coinbase-desktop-sdk, that disguise their behavior with fake npm install logs, trigger a bogus write-permissions error for "/usr/local/lib/node_modules," phish for sudo/root credentials, fetch a second-stage downloader from Telegram or Teletype.in, and deploy GhostLoader and a remote access trojan aimed at cryptocurrency wallets and sensitive data.
Show sources
- Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials — thehackernews.com — 24.03.2026 14:00
- Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials — thehackernews.com — 24.03.2026 14:00