掃碼下載
BTC $71,339.38 -2.98%
ETH $1,983.60 -0.77%
BNB $687.29 -3.11%
XRP $1.29 -2.42%
SOL $80.70 -1.12%
TRX $0.3451 -1.00%
DOGE $0.0998 +0.55%
ADA $0.2302 -1.06%
BCH $289.74 -2.76%
LINK $9.02 +0.09%
HYPE $72.41 +5.32%
AAVE $80.18 -1.24%
SUI $0.8762 +0.29%
XLM $0.2557 +3.99%
ZEC $550.54 +0.89%
BTC $71,339.38 -2.98%
ETH $1,983.60 -0.77%
BNB $687.29 -3.11%
XRP $1.29 -2.42%
SOL $80.70 -1.12%
TRX $0.3451 -1.00%
DOGE $0.0998 +0.55%
ADA $0.2302 -1.06%
BCH $289.74 -2.76%
LINK $9.02 +0.09%
HYPE $72.41 +5.32%
AAVE $80.18 -1.24%
SUI $0.8762 +0.29%
XLM $0.2557 +3.99%
ZEC $550.54 +0.89%

慢霧 CISO:警惕惡意 npm 包 “@openclaw-ai/openclawai”,其竊取加密錢包私鑰及系統憑證

2026-03-10 11:55:45
收藏

ChainCatcher 消息,据慢霧科技首席信息安全官 23pds 披露,情報系統發現名為 "@openclaw-ai/openclawai" 的惡意 npm 包正在實施多層攻擊。

該惡意包偽裝成名為 OpenClaw Installer 的合法命令行工具,旨在竊取用戶敏感信息,包括系統憑證、加密錢包私鑰、瀏覽器數據、SSH 密鑰以及 Apple Keychain 數據庫等。

app_icon
ChainCatcher 與創新者共建Web3世界