Ghost campaign malicious npm package operation
Campaign
Summary
Hide ▲
Show ▼
The Ghost campaign is pushing malicious npm packages that steal sudo/root credentials and enable wallet-targeting payloads, raising risk for developers using the Node.js ecosystem. The packages published by mikilanjillo use fake install logs and bogus permission errors to trick users into entering privileged passwords. Those credentials are then used to fetch staged payloads through Telegram, ending in a remote access trojan that can harvest data. The operation matters because it turns a trusted package-install workflow into a credential-theft and malware-delivery channel.
Related Happenings
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Malicious npm and PyPI payment SDK typosquat packages
Malware Activity
H score40
First: 09.07.2026 18:09
Last: 09.07.2026 18:09
Sources 1
About this happening:
The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Malicious npm and PyPI payment SDK typosquat packages
Malware ActivityAbout this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Hijacked npm and Go packages deploying Python infostealer via VS Code auto-run tasks
Malware Activity
H score30
First: 29.06.2026 08:36
Last: 29.06.2026 08:36
Sources 1
About this happening:
Hijacked npm and Go packages now deliver a Python infostealer through a hidden VS Code auto-run task, putting developer machines and credentials at risk across W...
Hijacked npm and Go packages deploying Python infostealer via VS Code auto-run tasks
Malware ActivityAbout this happening: Hijacked npm and Go packages now deliver a Python infostealer through a hidden VS Code auto-run task, putting developer machines and credentials at risk across W...
Timeline
-
24.03.2026 14:00 2 articles · 3mo ago
Ghost campaign malicious npm packages disclosed
Initial DisclosureReversingLabs tracks Ghost as a campaign in which 7 malicious npm packages published by mikilanjillo use fake install logs and a bogus write-permissions error to phish for sudo/root credentials, then retrieve a second-stage downloader through Telegram and deploy a remote access trojan that targets cryptocurrency wallets and other sensitive data.
Show sources
- Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials — thehackernews.com — 24.03.2026 14:00
- Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials — thehackernews.com — 24.03.2026 14:00