PULSE NAME
GhostClaw expands beyond npm: GitHub repositories and AI workflows deliver macOS infostealer
WHITE GhostClaw AlienVault 2026-03-23 Modified: 2026-03-23
17
IOCs
MEDIUM VOLUME
The GhostClaw malware campaign has expanded its distribution methods beyond npm packages to include GitHub repositories and AI-assisted development workflows. The attackers impersonate legitimate tools and utilize multi-stage payloads to steal credentials and retrieve additional malicious code. The infection chain involves executing shell commands, presenting fake authentication prompts, and establishing persistence. The campaign leverages both manual installation through README instructions and automated AI-assisted workflows. Multiple GitHub repositories have been identified, all communicating with a common command-and-control infrastructure. This shift in tactics allows the attackers to target a broader range of victims, including developers and users of AI-assisted coding tools.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
GhostClaw GhostLoader
Indicators of Compromise (17)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 189b8419863830f2732324a0e02e71721ec550ffa606f9dc719f935db5d25821 2026-03-23
FileHash-SHA256 3ab0bcc8ff821bd6ba0e5fdbb992836922a67524f8284d69324f61e651981040 2026-03-23
FileHash-SHA256 3c2fa99741e71436eb7f52fcf382bb92425104bd63f82d0bd0111caf2c8b91b4 2026-03-23
FileHash-SHA256 43dc96bde2d5214ea3e93c1d9f62da54c260587e0b5bd366bb55ab615262384e 2026-03-23
FileHash-SHA256 593aa8051b146e7b1effd90708210ccac3527076e2b5b5068216553a5557396d 2026-03-23
FileHash-SHA256 72bc4f82786e23f067d8731dac2b51c033f49ceceab0a64065a160cdff54f488 2026-03-23
FileHash-SHA256 8da42291c7c8ad4d7b174367c7b59e6cf57804f659490947957212d16dfcfe16 2026-03-23
FileHash-SHA256 946206d42497ea54a4df3f3fed262a99632672e99b02abcc7a9aff0f677efba8 2026-03-23
FileHash-SHA256 a80f2f5ba53bd19c35af5eed763fbaf9f00487bb4df0997651af861ef157ccea 2026-03-23
FileHash-SHA256 ad23c83bbcd2e2ed7ba3338b723f3a36ef7a6866672395a04fdb8fbd1bf68a90 2026-03-23
FileHash-SHA256 b04cdafdaa9220ab819f33790f014fd84a10f3908e3d7e97a652fa0d76f40c2f 2026-03-23
FileHash-SHA256 baaa13491ddaba1fc8eb5a3e7848fb1e33f6f1f5b19b5efb0d433ab09e38a1f0 2026-03-23
FileHash-SHA256 df8bc4bf6f312a914fa82e56dab59ceb0b2066830696ea7457067f7d446518eb 2026-03-23
FileHash-SHA256 e3ee5909f908b489a93702709fae038f0b3c864b155013a9ad7d590f1eec7fe4 2026-03-23
FileHash-SHA256 ec8d3b922db1cf3a82141a53a472538d10563860dfb93259e99d0aec3661734c 2026-03-23
FileHash-SHA256 ee968f51f1b2c0d9fcdacfd6aa9ef24cc6212118464093e67f1fdaa1144e15b1 2026-03-23
domain trackpipe.dev 2026-03-23