Scan to download
BTC $65,671.72 +1.90%
ETH $1,717.43 +2.19%
BNB $616.45 +1.17%
XRP $1.19 +3.14%
SOL $71.09 +3.25%
TRX $0.3207 +1.61%
DOGE $0.0888 +1.19%
ADA $0.1814 +5.28%
BCH $211.08 +1.42%
LINK $8.18 +3.09%
HYPE $65.17 +8.20%
AAVE $69.12 +3.19%
SUI $0.7994 +4.32%
XLM $0.1897 +2.25%
ZEC $488.35 +15.96%
BTC $65,671.72 +1.90%
ETH $1,717.43 +2.19%
BNB $616.45 +1.17%
XRP $1.19 +3.14%
SOL $71.09 +3.25%
TRX $0.3207 +1.61%
DOGE $0.0888 +1.19%
ADA $0.1814 +5.28%
BCH $211.08 +1.42%
LINK $8.18 +3.09%
HYPE $65.17 +8.20%
AAVE $69.12 +3.19%
SUI $0.7994 +4.32%
XLM $0.1897 +2.25%
ZEC $488.35 +15.96%

Slow Fog CISO: Beware of the malicious npm package "@openclaw-ai/openclawai," which steals cryptocurrency wallet private keys and system credentials

2026-03-10 11:55:45
Collection

According to 23pds, the Chief Information Security Officer of Slow Fog Technology, an intelligence system has discovered a malicious npm package named "@openclaw-ai/openclawai" that is implementing a multi-layer attack.

This malicious package disguises itself as a legitimate command-line tool called OpenClaw Installer, aimed at stealing sensitive user information, including system credentials, cryptocurrency wallet private keys, browser data, SSH keys, and Apple Keychain database, among others.

app_icon
ChainCatcher Building the Web3 world with innovations.