New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide Malware

2026-03-24T14:52:22Z202b2b4ba46f49e7a12c03ecfe4b9631f8c4d3aa096c4b1f506bcdc899d16518
CI/CD compromiseCISACVE-2026-20131CVE-2026-3888CiscoDockerHandalaLangflowMFA bypassRATTeamPCPTrivyUbuntuinfostealermalwaren8nnpmprivilege escalationransomwaresudo credential theftsupply-chainsupply-chain securitytycoon2favulnerability exploitzero-click

What happened

Feed highlights a surge in active malware campaigns and rapidly exploited vulnerabilities across open-source ecosystems, cloud services and networking equipment. Notable incidents: a 'Ghost' npm campaign that spoofs install logs to steal sudo credentials and deploy RATs; Trivy Docker images (0.69.5/0.69.6) compromised with TeamPCP infostealer affecting CI/CD scans; CISA-ordered patching for Cisco vulnerability CVE-2026-20131 being used in ransomware attacks; a critical zero-click n8n flaw allowing full server compromise; a critical Langflow vulnerability exploited within 20 hours; Ubuntu local

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
202b2b4ba46f49e7a12c03ecfe4b9631f8c4d3aa096c4b1f506bcdc899d16518
Enrichment time
2026-03-24T14:52:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide Malware · Baitaphish