Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials
A new set of malicious npm packages that are intended to steal sensitive data and cryptocurrency wallets has been discovered by cybersecurity researchers.
ReversingLabs is monitoring the behavior as part of the Ghost campaign. Below is a list of the packages that have been identified, all of which were released by the user mikilanjillo:
react-performance-suite
react-state-optimizer-core
react-fast-utilsa
ai-fast-auto-trader
pkgnewfefame1
coinbase-desktop-sdk
According to a report shared with The Hacker News by Lucija Valentić, a software threat researcher at ReversingLabs, the packages themselves are phishing for the sudo password that is used to execute the final stage. They are attempting to conceal their true functionality and evade detection by displaying pho...








