News
Malware GhostClaw Steals Developer Crypto Wallet Data Through npm Package
en
On March 23, according to Cryptopolitan, a new malware called GhostClaw is targeting crypto wallets on macOS devices. The malware, disguised as a legitimate OpenClaw CLI tool, existed in the npm registry for a week and infected 178 developers before being removed on March 10. Once developers run the "npm install" command, a hidden script globally installs the GhostClaw package and evades detection through obfuscated configuration files.
GhostClaw scans the clipboard every three seconds, capturing crypto wallet and transaction-related data such as private keys, mnemonic phrases, and public keys. After the second stage payload is downloaded, GhostLoader scans Chromium browsers, macOS Keychain, and system storage for crypto wallet data, clones browser sessions to gain access to logged-in wallets, and steals API tokens connected to AI platforms like OpenAI and Anthropic. The stolen data is sent to attackers via Telegram, GoFile, and command servers.