Find notable cyber news and cases, enriched with sources, timelines, and signals.

GhostLoader staged npm install payload activity

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

GhostLoader is now being delivered through staged npm install scripts, turning routine package installation into a route for data theft and cryptocurrency wallet targeting. The chain uses fake install logs and a bogus permissions error to push developers into revealing a sudo/root password. After that step, the malware retrieves a downloader that connects to C2 infrastructure and fetches the final payload. The result is a remote access trojan that can harvest data, focus on wallets, and wait for further instructions.

Related Happenings

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

BoryptGrab infostealer variant delivered via fake GitHub repositories

Malware Activity
H score30 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...

CrashStealer macOS information stealer activity

Malware Activity
H score10 First: 13.07.2026 20:36 Last: 13.07.2026 20:36 Sources 1

About this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...

Jscrambler 8.14.0 malicious preinstall infostealer release

Malware Activity
H score9 First: 11.07.2026 20:59 Last: 11.07.2026 20:59 Sources 1

About this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...

QuimaRAT cross-platform Java MaaS remote access trojan

Malware Activity
H score29 First: 06.07.2026 11:13 Last: 06.07.2026 11:13 Sources 1

About this happening: A new QuimaRAT MaaS offering expands cross-platform malware risk by packaging a modular Java-based RAT for Windows, Linux, and macOS. The activity matters because...

Timeline

  1. 24.03.2026 14:00 2 articles · 3mo ago

    ReversingLabs identifies malicious npm packages published by mikilanjillo

    Initial Disclosure

    Security researchers identify seven malicious npm packages published by mikilanjillo, including react-performance-suite, react-state-optimizer-core, react-fast-utilsa, ai-fast-auto-trader, pkgnewfefame1, carbon-mac-copy-cloner, and coinbase-desktop-sdk, that disguise their behavior with fake npm install logs, trigger a bogus write-permissions error for "/usr/local/lib/node_modules," phish for sudo/root credentials, fetch a second-stage downloader from Telegram or Teletype.in, and deploy GhostLoader and a remote access trojan aimed at cryptocurrency wallets and sensitive data.

    Show sources