Scan to download
BTC $65,546.03 +1.53%
ETH $1,722.81 +2.42%
BNB $614.77 +0.92%
XRP $1.17 +1.94%
SOL $70.51 +2.31%
TRX $0.3197 +0.86%
DOGE $0.0883 +0.60%
ADA $0.1762 +2.50%
BCH $208.97 +0.26%
LINK $8.11 +1.67%
HYPE $63.54 +5.14%
AAVE $67.79 +1.16%
SUI $0.7868 +2.68%
XLM $0.1880 +0.62%
ZEC $467.79 +11.29%
BTC $65,546.03 +1.53%
ETH $1,722.81 +2.42%
BNB $614.77 +0.92%
XRP $1.17 +1.94%
SOL $70.51 +2.31%
TRX $0.3197 +0.86%
DOGE $0.0883 +0.60%
ADA $0.1762 +2.50%
BCH $208.97 +0.26%
LINK $8.11 +1.67%
HYPE $63.54 +5.14%
AAVE $67.79 +1.16%
SUI $0.7868 +2.68%
XLM $0.1880 +0.62%
ZEC $467.79 +11.29%

Slow Fog CISO: Beware of the malicious npm package "@openclaw-ai/openclawai," which steals cryptocurrency wallet private keys and system credentials

2026-03-10 11:55:45
Collection

According to 23pds, the Chief Information Security Officer of Slow Fog Technology, an intelligence system has discovered a malicious npm package named "@openclaw-ai/openclawai" that is implementing a multi-layer attack.

This malicious package disguises itself as a legitimate command-line tool called OpenClaw Installer, aimed at stealing sensitive user information, including system credentials, cryptocurrency wallet private keys, browser data, SSH keys, and Apple Keychain database, among others.

app_icon
ChainCatcher Building the Web3 world with innovations.