GhostClaw , a macOS malware that steals information, is spreading through GitHub repositories and development tools, exploiting users’ installation habits that make running malware seem completely normal. Jamf researchers tracked the campaign ’s shift from npm packages to GitHub repositories and AI-powered development environments.
See also: AWS CodeBuild: Misconfiguration put GitHub repos at risk

The payload, a malicious software for macOS that steals information, integrates into normal behavior instead of exploiting the software.
Developers often download code from GitHub, follow the README , and run installation commands without much thought. Familiar processes build trust, and GhostClaw taps right into that routine. This campaign shows how developers’ habits can be used to spread malware, without requiring the exploitation of software vulnerabilities.
Jamf reports that GhostClaw uses GitHub repositories to distribute its malicious software, exploiting the trust developers have in these repositories. Developers often do not pay much attention when following installation instructions, which GhostClaw exploits to infiltrate systems.
See also: WebRAT malware distributed via fake PoC exploits on GitHub

This campaign emphasizes the need for increased vigilance and control when installing software from GitHub repositories. Developers must be especially careful and verify the authenticity of repositories before executing any commands. Using security tools to detect malicious software can also help protect systems from such threats.
Jamf also recommends training developers on best security practices and recognizing potential threats. Understanding the risks and taking preventive measures can significantly reduce the likelihood of a successful attack by malware such as GhostClaw.
See also: Sensitive credentials leaked from AI startups on GitHub

The spread of GhostClaw via GitHub shows how easy it is for malicious actors to exploit users' habits and distribute malicious software. It is essential for developers to stay continuously informed about the latest threats and to take the necessary measures to protect their systems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
