Scan to download
BTC $77,194.69 +0.31%
ETH $2,325.53 +1.61%
BNB $627.53 +0.27%
XRP $1.39 +0.08%
SOL $84.79 +0.75%
TRX $0.3217 -0.71%
DOGE $0.1018 +1.88%
ADA $0.2492 +0.53%
BCH $454.08 +1.30%
LINK $9.36 +0.82%
HYPE $40.49 -1.97%
AAVE $97.60 -0.23%
SUI $0.9341 +0.21%
XLM $0.1633 -1.08%
ZEC $338.30 -0.53%
BTC $77,194.69 +0.31%
ETH $2,325.53 +1.61%
BNB $627.53 +0.27%
XRP $1.39 +0.08%
SOL $84.79 +0.75%
TRX $0.3217 -0.71%
DOGE $0.1018 +1.88%
ADA $0.2492 +0.53%
BCH $454.08 +1.30%
LINK $9.36 +0.82%
HYPE $40.49 -1.97%
AAVE $97.60 -0.23%
SUI $0.9341 +0.21%
XLM $0.1633 -1.08%
ZEC $338.30 -0.53%

Slow Fog CISO: Beware of the malicious npm package "@openclaw-ai/openclawai," which steals cryptocurrency wallet private keys and system credentials

2026-03-10 11:55:45
Collection

According to 23pds, the Chief Information Security Officer of Slow Fog Technology, an intelligence system has discovered a malicious npm package named "@openclaw-ai/openclawai" that is implementing a multi-layer attack.

This malicious package disguises itself as a legitimate command-line tool called OpenClaw Installer, aimed at stealing sensitive user information, including system credentials, cryptocurrency wallet private keys, browser data, SSH keys, and Apple Keychain database, among others.

app_icon
ChainCatcher Building the Web3 world with innovations.