Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

A new set of malicious npm packages that are intended to steal sensitive data and cryptocurrency wallets has been discovered by cybersecurity researchers.

ReversingLabs is monitoring the behavior as part of the Ghost campaign. Below is a list of the packages that have been identified, all of which were released by the user mikilanjillo:

  • react-performance-suite
  • react-state-optimizer-core
  • react-fast-utilsa
  • ai-fast-auto-trader
  • pkgnewfefame1
  • coinbase-desktop-sdk

According to a report shared with The Hacker News by Lucija Valentić, a software threat researcher at ReversingLabs, the packages themselves are phishing for the sudo password that is used to execute the final stage. They are attempting to conceal their true functionality and evade detection by displaying phony npm install logs.

In addition to making fraudulent claims about downloading extra packages, the detected Node.js libraries introduce arbitrary delays to create the appearance that the installation process is in progress read more about Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *