Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials
The Hacker News | #1 Trusted Source for Cybersecurity News [Uno…
March 24, 2026
Cybersecurity researchers have uncovered a new set of malicious npm packages that are designed to steal cryptocurrency wallets and sensitive data.
The activity is being tracked by ReversingLabs as the Ghost campaign. The list of identified packages, all published by a user named mikilanjillo, is below -
react-performance-suite
react-state-optimizer-core
react-fast-utilsa
ai-fast-auto-trader
Discussion in the ATmosphere