Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign

A new and carefully crafted software supply chain campaign is targeting developers through the npm package registry, using fake installation messages to hide malicious activity. The campaign, which security researchers have named the “Ghost campaign,” began in early February 2026 and relies on a set of npm packages built to deceive developers into surrendering their […]

The post Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: