GhostLoader is a cross-platform information-stealing malware framework associated with the broader GhostClaw activity cluster and heavily focused on developer environments, AI-assisted workflows, and software supply-chain abuse. It has been distributed through malicious OpenClaw-themed GitHub repositories and a rogue npm package masquerading as an OpenClaw installer, where npm lifecycle scripts and obfuscated Node.js stages trigger infection on macOS, Linux, and Windows. In some campaigns, GhostLoader was delivered through manual installation paths, while automated Windows installation paths instead deployed Remcos RAT.
The malware is designed to harvest high-value secrets from developer workstations and adjacent cloud environments. Reported collection targets include system passwords obtained through fake authentication prompts, macOS Keychain data, browser credentials and cookies, cryptocurrency wallets and seed phrases, SSH keys, cloud and developer credentials for major platforms, package-manager tokens, GitHub-related secrets, Kubernetes and Docker configuration, and AI-agent or MCP-related configuration files. On macOS and Linux, GhostLoader has used terminal-based social engineering, including spoofed password prompts, to capture credentials and unlock protected data stores.
GhostLoader supports broad data exfiltration and has been observed stealing sensitive developer data from compromised hosts. Some variants also establish persistence by installing hidden telemetry-themed components, modifying shell startup files, and using scheduled relaunch mechanisms such as cron. Beyond pure theft, later-stage GhostLoader functionality has included remote command execution, SOCKS5 proxying, and browser session cloning, giving it RAT-like post-compromise utility even though its primary role is credential and data theft.
The malware has been linked to campaigns that impersonate trusted developer tools and AI integrations, including fake OpenClaw skills and installer packages. Targeting has centered on software developers, cloud-focused engineering environments, and organizations adopting AI agent tooling, with overlap in campaigns aimed at cryptocurrency holders and other users likely to possess monetizable credentials or wallet material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Jamf Threat Labs exposes new GhostClaw/GhostLoader samples using malicious GitHub repos and AI dev workflows to steal macOS credentials via multi-stage payloads.
The supply-chain pattern that emerged in the first half of 2026... targets the packages and tokens developers plug in automatically, reaching everyone downstream in a single operation.
"identified a live malicious npm package named @openclaw-ai/openclawai ... masquerades as a legitimate CLI tool"
the repositories contain a README with step-by-step installation instructions that encourage users to execute a shell command, typically using curl to retrieve and run a remote script.
A new malware campaign called GhostClaw is actively targeting macOS users through fake GitHub repositories and AI-assisted development workflows. The campaign uses social engineering disguised as legitimate developer tools to steal user credentials and drop secondary payloads on infected systems.
This retrieves and executes install.sh, which serves as the initial bootstrapper.
The alternate attack path, built for macOS and Linux environments, used a heavily obfuscated Node.js file buried inside npm lifecycle scripts. When the install command ran, it silently dropped GhostLoader onto the system.
For macOS and Linux systems, the campaign deploys an obfuscated Node.js payload that installs GhostLoader to steal sensitive developer data.
"The NUKE command performs complete self-destruction... removes shell hooks... cleans cron jobs... deletes ... install directory"
enabling it steal system credentials, deliver the GhostLoader malware by contacting a command-and-control (C2) server, and remove traces of malicious activity by clearing the Terminal.
Following execution, the temporary file is removed... Following execution of the primary payload, postinstall.js is invoked to extend the compromise and obscure earlier activity.
"displays a fake Keychain authorization prompt... victim is prompted for their system password (up to 5 attempts)"
Remcos set itself to stealth mode immediately upon execution, logging keystrokes, stealing browser cookies... With Remcos giving attackers a full remote shell and GhostLoader scooping up cloud tokens, SSH keys, and browser session cookies...
A developer-focused module sweeps SSH keys, cloud credentials, and package manager tokens... The malware sweeping through these environments specifically targeted GitHub auth tokens, AWS/Azure/GCP credentials, SSH keys...
the next-stage downloader... reaches out to a Telegram channel to fetch the URL for the final payload... The initial npm package captures credentials and fetches configuration from either a Telegram channel or a Teletype.in page...
"HTTP upload to hxxps://trackpipe.dev" and "polls the C2 panel every ~25 seconds"
"installs a persistent RAT... including a SOCKS5 proxy" and "PROXY_START Start a SOCKS5 proxy"
Once active, GhostLoader swept through the host for anything valuable: macOS Keychain data, SSH keys, cryptocurrency wallet files, and cloud API tokens. All of it was sent back to attacker-controlled servers.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware associated with fake AI-tool lures and credential theft from AI-agent and developer environments.
An obfuscated Node.js-delivered payload used on macOS and Linux to steal sensitive developer data.
A cross-platform stealer delivered through obfuscated Node.js code in npm lifecycle scripts from the fake DeepSeek-Claw skill. It targets developer environments, steals macOS Keychain data, SSH keys, cryptocurrency wallet files, cloud API tokens, and browser/session-related data, and exfiltrates them to attacker-controlled servers. On macOS and Linux it also presents fake password prompts to harvest credentials.
Cross-platform information stealer targeting developer environments. In this campaign it is delivered through manual installation paths such as install.sh or npm install, including an obfuscated Node.js payload. It harvests credentials via terminal-based social engineering and exfiltrates macOS keychain data, SSH keys, cryptocurrency wallets, and cloud API tokens.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.