Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

2026-03-24T13:24:20Zf013229c731f62bd6e49fb76b01467004cd45bd4e2d8f2686921b122e2416fd5
byovdcanisterwormci-cdcisacredential-theftcryptocurrency-theftdockerdoj-takedownedr-bypassgithub-actionsinfostealeriot-botnetmalicious-packagesnpmpatch-nowphishingrcestoatwafflesupply-chainteampcptrivyunauthenticated-exploitvs-codewaterplumwiper

What happened

The collection highlights multiple high-impact supply‑chain and exploitation events: a Ghost campaign pushing malicious npm packages to steal crypto and credentials; follow‑on Trivy supply‑chain compromises (including CanisterWorm) that spread infostealers via Docker and hijacked GitHub Actions to exfiltrate CI/CD secrets; TeamPCP compromises of Checkmarx workflows; and new malware families (StoatWaffle, Speagle) distributed via developer tools (VS Code, compromised servers). Several critical, actively exploited vulnerabilities and vendor advisories require immediate patching (Citrix, Oracle,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
f013229c731f62bd6e49fb76b01467004cd45bd4e2d8f2686921b122e2416fd5
Enrichment time
2026-03-24T13:24:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.