You should check ssh logs
Can you share the install log of ghost?
The app is run using a restricted system user. So it won’t be possible for a compromised app to get root access unless privilge escalation bug. You are already on the latest version of yunohost, there have been a lot of serious vulnerabilities related to Linux kernel some months ago [CVE-2026-43284 "Dirty Frag"] Upgrade your system packages
Now you can run malware scanners on your server
Do not open your ssh port outside.
Also, run yunohost tools regen-conf --dry-run --with-diff to see if any config files have been altered.