
Security specialists have discovered new harmful npm packages created to pilfer cryptocurrency wallets and private information.
ReversingLabs is calling this the Ghost operation. The packages identified, all from user mikilanjillo, include:
“These packages trick users into giving their sudo password to execute the final stage. They cleverly hide their true purpose to avoid detection by showing fake npm install progress,” said Lucija Valentić, a ReversingLabs software threat researcher, in a report to The Hacker News.
Besides falsely claiming to download more programs, these Node.js libraries add random delays to mimic an ongoing installation. They then falsely claim an installation error due to a lack of write permissions to “/usr/local/lib/node_modules,” the standard location for global Node.js packages on Linux and macOS.
The malware prompts the user for their root or admin password to continue. If entered, it secretly downloads the next-stage downloader, which contacts a Telegram channel for the final payload’s URL and decryption key.
The attack culminates in a remote access trojan that steals data, targets cryptocurrency wallets, and awaits instructions from an external server.
ReversingLabs noted similarities to the GhostClaw activity documented by JFrog earlier in the month, but it’s unclear if it’s the same group or a new campaign.
Jamf Threat Labs reported last week that GhostClaw uses GitHub repositories and AI-assisted development to distribute credential-stealing malware on macOS.
“These repositories mimic legitimate tools, such as trading bots, SDKs, and developer utilities, to appear credible,” said security researcher Thijs Xhaflaire said. “Some repositories had significant user interaction, with hundreds of stars, further enhancing their perceived legitimacy.”
In this operation, the repositories initially contain harmless or partially working code that remains untouched for an extended period to build trust before the malicious elements are added. These repositories often include a README file that instructs developers to run a shell script during installation.
Some repositories have a SKILL.md file, designed for AI-centric workflows, that purports to install external skills using AI agents like OpenClaw. Regardless of the method, the shell script starts a multi-stage infection leading to a data-stealing program. The process involves these steps:
The script includes an environment variable called “GHOST_PASSWORD_ONLY.” When set to zero, it presents a complete interactive installation with progress bars and prompts. If set to 1, it uses a streamlined path focusing on credential collection without extra UI elements.
In some instances, the “postinstall.js” script displays a benign success message indicating successful installation and instructing users to configure the library in their projects using the “npx react-state-optimizer” command.
A report from cloud security company Panther last month indicated that “react-state-optimizer” is one of several npm packages published by “mikilanjillo,” suggesting the two activities are related:
“The packages include a CLI ‘setup wizard’ that prompts developers for their sudo password to perform ‘system optimizations,'” stated security researcher Alessandra Rizzo. “The obtained password is then sent to a comprehensive credential stealer that gathers browser credentials, cryptocurrency wallets, SSH keys, cloud provider configurations, and developer tool tokens.”
“Stolen data is sent to partner-specific Telegram bots based on a campaign identifier embedded in each loader, with credentials stored in the BSC smart contract and updated without modifying the malware.”
The initial npm package steals credentials and pulls configuration from a Telegram channel or a Teletype.in page disguised as blockchain documentation to deploy the stealer. Panther notes the malware uses a dual revenue model, primarily from stolen credentials sent through partner Telegram channels, and secondarily through affiliate URL redirects in a separate Binance Smart Chain (BSC) smart contract.
“This highlights a continued shift in attacker techniques, extending beyond traditional repositories to platforms like GitHub and emerging AI-assisted development workflows,” Jamf said. “By using trusted platforms and standard installation procedures, attackers can introduce malicious code into environments smoothly.”
#and #attack #credentials #crypto #for #ghost #leverages #news #npm #packages #seven #targeted #theft #wallets — News
© Bulletproof Servers. All rights reserved.