A new malware named GhostClaw is targeting macOS devices' crypto wallets. According to PANews, the malware masqueraded as a legitimate OpenClaw CLI tool and was available on the npm registry for a week before being removed on March 10 after infecting 178 developers. When developers executed the 'npm install' command, a hidden script globally installed the GhostClaw package, using obfuscated configuration files to evade detection.
GhostClaw scans the clipboard every three seconds to capture private keys, mnemonic phrases, public keys, and other crypto wallet and transaction-related data. In its second stage, GhostLoader downloads additional payloads, scanning Chromium browsers, macOS keychains, and system storage for crypto wallet data. It clones browser sessions to access logged-in wallets and steals API tokens connected to AI platforms like OpenAI and Anthropic. The stolen data is sent to attackers via Telegram, GoFile, and command servers.