Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials
2026-03-24T13:24:20Z•f013229c731f62bd6e49fb76b01467004cd45bd4e2d8f2686921b122e2416fd5
byovdcanisterwormci-cdcisacredential-theftcryptocurrency-theftdockerdoj-takedownedr-bypassgithub-actionsinfostealeriot-botnetmalicious-packagesnpmpatch-nowphishingrcestoatwafflesupply-chainteampcptrivyunauthenticated-exploitvs-codewaterplumwiper
What happened
The collection highlights multiple high-impact supply‑chain and exploitation events: a Ghost campaign pushing malicious npm packages to steal crypto and credentials; follow‑on Trivy supply‑chain compromises (including CanisterWorm) that spread infostealers via Docker and hijacked GitHub Actions to exfiltrate CI/CD secrets; TeamPCP compromises of Checkmarx workflows; and new malware families (StoatWaffle, Speagle) distributed via developer tools (VS Code, compromised servers). Several critical, actively exploited vulnerabilities and vendor advisories require immediate patching (Citrix, Oracle,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- f013229c731f62bd6e49fb76b01467004cd45bd4e2d8f2686921b122e2416fd5
- Enrichment time
- 2026-03-24T13:24:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.