GhostClaw is a macOS-focused malware campaign targeting developers through software supply chain and social-engineering lures. It has been associated with malicious npm packages and GitHub repositories impersonating developer tools such as SDKs, trading bots, and OpenClaw-related projects. The campaign also abuses AI-assisted development workflows by embedding malicious instructions in repository content that can be executed by coding agents, enabling compromise with limited or no direct user interaction.
The infection chain is multi-stage. Initial access has been observed through malicious npm package installation hooks and through repository instructions that persuade victims to run shell commands. On execution, GhostClaw deploys a bootstrapper that profiles the host, installs a compatible Node.js runtime in user space without requiring elevated privileges, and launches an obfuscated JavaScript stage. The malware uses fake installer output and deceptive prompts to make the activity appear legitimate.
A core function of GhostClaw is credential theft. It prompts victims for their macOS password under false pretenses and validates the supplied credential using native system functionality. It also uses deceptive AppleScript dialogs resembling legitimate macOS security prompts in an attempt to obtain broader access, including Full Disk Access. Subsequent stages retrieve encrypted payloads from attacker-controlled infrastructure, execute them in the background, and remove temporary artifacts to reduce visibility.
GhostClaw establishes persistence on compromised systems by placing components in user-controlled locations chosen to resemble normal npm telemetry or developer tooling activity. Reported activity indicates overlap in techniques and infrastructure with related clusters referred to as GhostLoader and the broader Ghost campaign. The campaign is notable for blending developer trust in public code repositories and package ecosystems with modern AI-driven development practices to compromise macOS systems and steal credentials and other sensitive data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Jamf Threat Labs exposes new GhostClaw/GhostLoader samples using malicious GitHub repos and AI dev workflows to steal macOS credentials via multi-stage payloads.
JFrog found the malicious package @openclaw-ai/openclawai on npm... The package used a postinstall hook to reinstall itself globally...
the repositories contain a README with step-by-step installation instructions that encourage users to execute a shell command, typically using curl to retrieve and run a remote script.
A new malware campaign called GhostClaw is actively targeting macOS users through fake GitHub repositories and AI-assisted development workflows. The campaign uses social engineering disguised as legitimate developer tools to steal user credentials and drop secondary payloads on infected systems.
In one path, repositories contain README files with step-by-step installation instructions that prompt users to run a shell command using curl.
Execution then passes to setup.js, a heavily obfuscated JavaScript file responsible for credential collection.
In the rankings of malicious samples by the file names attackers gave them, impersonations of AI developer tools... now sit second only to cracked Adobe and creative-suite installers... Fake corporate meeting apps (Zoom, Teams, Webex)...
Following execution, the temporary file is removed... Following execution of the primary payload, postinstall.js is invoked to extend the compromise and obscure earlier activity.
These dialogs are designed to resemble macOS security prompts and instruct the user to grant access or provide credentials. Variants observed during analysis impersonate different applications, including developer tools and trading platforms, while maintaining consistent messaging around access to 'secure wallet and credential storage.'
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware delivered via a malicious npm package impersonating OpenClaw. It used a postinstall hook, fake CLI installer prompts, password harvesting, retrieval of an encrypted second-stage payload, decryption, temporary-file execution as a detached background process, and cleanup of the dropped file.
GhostClaw is a macOS-focused malware campaign delivered via malicious npm packages and fake GitHub repositories impersonating developer tools. It uses social engineering and AI-agent-targeted SKILL.md files to trigger infection, installs Node.js without elevated privileges, steals user credentials by validating them with dscl, retrieves an encrypted secondary payload from C2 infrastructure, and establishes persistence under a path designed to resemble normal npm telemetry activity.
A remote access trojan delivered via malicious npm packages in a software supply chain campaign. It uses fake npm installation logs and sudo password phishing to deploy a final payload, then steals cryptocurrency wallets, harvests sensitive data, and accepts remote commands while maintaining stealthy persistence.
Remote Access Trojan (RAT) delivered to developers searching for 'OpenClaw', implying a trojanized/masquerading distribution to gain remote control of victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.