Scan to download
BTC $77,095.58 +0.27%
ETH $2,327.94 +1.84%
BNB $626.50 +0.22%
XRP $1.39 +0.13%
SOL $84.80 +0.76%
TRX $0.3221 -0.57%
DOGE $0.1021 +2.22%
ADA $0.2491 +0.76%
BCH $453.57 +1.34%
LINK $9.35 +0.71%
HYPE $40.59 -1.62%
AAVE $97.33 -0.54%
SUI $0.9317 -0.05%
XLM $0.1635 -0.80%
ZEC $336.33 -0.10%
BTC $77,095.58 +0.27%
ETH $2,327.94 +1.84%
BNB $626.50 +0.22%
XRP $1.39 +0.13%
SOL $84.80 +0.76%
TRX $0.3221 -0.57%
DOGE $0.1021 +2.22%
ADA $0.2491 +0.76%
BCH $453.57 +1.34%
LINK $9.35 +0.71%
HYPE $40.59 -1.62%
AAVE $97.33 -0.54%
SUI $0.9317 -0.05%
XLM $0.1635 -0.80%
ZEC $336.33 -0.10%

Slow Fog CISO: Beware of the malicious npm package "@openclaw-ai/openclawai," which steals cryptocurrency wallet private keys and system credentials

2026-03-10 11:55:45
Collection

According to 23pds, the Chief Information Security Officer of Slow Fog Technology, an intelligence system has discovered a malicious npm package named "@openclaw-ai/openclawai" that is implementing a multi-layer attack.

This malicious package disguises itself as a legitimate command-line tool called OpenClaw Installer, aimed at stealing sensitive user information, including system credentials, cryptocurrency wallet private keys, browser data, SSH keys, and Apple Keychain database, among others.

app_icon
ChainCatcher Building the Web3 world with innovations.