Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ghost campaign malicious npm package operation

Campaign
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

The Ghost campaign is pushing malicious npm packages that steal sudo/root credentials and enable wallet-targeting payloads, raising risk for developers using the Node.js ecosystem. The packages published by mikilanjillo use fake install logs and bogus permission errors to trick users into entering privileged passwords. Those credentials are then used to fetch staged payloads through Telegram, ending in a remote access trojan that can harvest data. The operation matters because it turns a trusted package-install workflow into a credential-theft and malware-delivery channel.

Related Happenings

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

Jscrambler 8.14.0 malicious preinstall infostealer release

Malware Activity
H score9 First: 11.07.2026 20:59 Last: 11.07.2026 20:59 Sources 1

About this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...

Malicious npm and PyPI payment SDK typosquat packages

Malware Activity
H score40 First: 09.07.2026 18:09 Last: 09.07.2026 18:09 Sources 1

About this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
H score16 First: 03.07.2026 19:07 Last: 03.07.2026 19:07 Sources 1

About this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...

Hijacked npm and Go packages deploying Python infostealer via VS Code auto-run tasks

Malware Activity
H score30 First: 29.06.2026 08:36 Last: 29.06.2026 08:36 Sources 1

About this happening: Hijacked npm and Go packages now deliver a Python infostealer through a hidden VS Code auto-run task, putting developer machines and credentials at risk across W...

Timeline

  1. 24.03.2026 14:00 2 articles · 3mo ago

    Ghost campaign malicious npm packages disclosed

    Initial Disclosure

    ReversingLabs tracks Ghost as a campaign in which 7 malicious npm packages published by mikilanjillo use fake install logs and a bogus write-permissions error to phish for sudo/root credentials, then retrieve a second-stage downloader through Telegram and deploy a remote access trojan that targets cryptocurrency wallets and other sensitive data.

    Show sources