Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Cardano shorts dominate 75% of ADA exposure – Is confidence breaking?

June 4, 2026

Qingdao Prosecutors Rule Bitcoin Qualifies as Property Under Chinese Criminal Law in Landmark Theft Case

June 4, 2026

ENI, Noos Protocol Advance AI-Powered Coordination Layer for Decentralized Networks

June 4, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»New Npm ‘Ghost Campaign’ Uses Fake Install Logs to Hide Malware
New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide Malware
Security and Privacy

New Npm ‘Ghost Campaign’ Uses Fake Install Logs to Hide Malware

March 24, 2026No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A new malicious npm campaign using fake installation logs to hide malware activity has been identified by security researchers.

The attacks, discovered by ReversingLabs, involve malicious packages that mimic legitimate software installation processes while secretly downloading and executing malware designed to steal sensitive data and crypto wallets.

The campaign, dubbed the “Ghost campaign,” began in early February and includes several malicious packages with downloader functionality. These packages attempt to obtain a user’s sudo password during installation, which is later used to execute a remote access trojan (RAT) on the victim’s system.

Fake Installation Logs Used as Cover

Researchers found that the malicious packages displayed fake npm install logs to make the installation process appear legitimate.

The logs included messages about downloading dependencies, installation progress bars and random delays to simulate real installation activity. In reality, none of these actions took place.

At one point during the fake installation, users were prompted to enter their sudo password to fix a supposed installation issue or perform optimization tasks. Once entered, the password was used to execute the final malware stage without the user noticing.

Read more on supply chain attacks: Trivy Supply Chain Attack Expands With New Compromised Docker Images

The final malware payload was downloaded from external sources, including a Telegram channel and hidden web3 content. The payload was then decrypted using a key retrieved online and executed locally using the stolen sudo password.

Malware Designed to Steal Crypto and Sensitive Data

The final-stage malware was a remote access trojan capable of stealing crypto wallets, collecting sensitive information and receiving commands from a command-and-control (C2) server. Some versions included additional files that enhanced data theft capabilities.

See also  PyRo Mine Malware Uses NSA Tool to Collect Monero

Researchers noted that several packages shared similar code structures and techniques, suggesting either a new campaign or an early test run of a larger operation. Similar methods were also observed in other recently reported malicious npm packages.

Researchers recommend several steps to reduce exposure to malicious open-source packages:

  • Verify package authors and repository history

  • Monitor installation scripts and unusual prompts

  • Use automated security scanning tools

  • Avoid entering sudo passwords during package installation

ReversingLabs said they will continue monitoring npm repositories for similar threats and flag malicious packages as they are discovered.

Source link

campaign fake Ghost hide Install logs Malware npm
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

New DeFi entrant widens field of crypto political campaign funds as elections loom

June 3, 2026

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

June 3, 2026

U.S. says it seized about $1 billion in Iranian crypto as pressure campaign expands

May 31, 2026

SEC sues Texas man over $12.3 million alleged crypto scheme built on fake AI trading bots

May 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Cardano: Will rising DEX volumes bear fruit for ADA?

January 16, 2024

Bitcoin ETF demand cracks after CLARITY Act vote

May 21, 2026

How to use a VPN for online security and privacy

May 21, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Cardano shorts dominate 75% of ADA exposure – Is confidence breaking?

June 4, 2026

Qingdao Prosecutors Rule Bitcoin Qualifies as Property Under Chinese Criminal Law in Landmark Theft Case

June 4, 2026

ENI, Noos Protocol Advance AI-Powered Coordination Layer for Decentralized Networks

June 4, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,670.00-1.76%
  • ethereumEthereum(ETH)$1,766.87-3.20%
  • tetherTether(USDT)$1.000.03%
  • binancecoinBNB(BNB)$602.34-3.82%
  • usd-coinUSDC(USDC)$1.000.01%
  • rippleXRP(XRP)$1.17-3.24%
  • solanaSolana(SOL)$68.35-5.17%
  • tronTRON(TRX)$0.331194-0.62%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.021.52%
  • HyperliquidHyperliquid(HYPE)$64.31-13.63%