Scan to download
BTC $59,455.87 -0.64%
ETH $1,585.19 +0.46%
BNB $551.91 -0.16%
XRP $1.04 -0.46%
SOL $73.93 +2.27%
TRX $0.3192 -0.78%
DOGE $0.0722 -0.91%
ADA $0.1442 -0.10%
BCH $198.78 +2.43%
LINK $7.28 -0.23%
HYPE $65.65 +5.03%
AAVE $89.90 -4.19%
SUI $0.6945 +1.06%
XLM $0.1832 +6.04%
ZEC $398.76 +5.06%
BTC $59,455.87 -0.64%
ETH $1,585.19 +0.46%
BNB $551.91 -0.16%
XRP $1.04 -0.46%
SOL $73.93 +2.27%
TRX $0.3192 -0.78%
DOGE $0.0722 -0.91%
ADA $0.1442 -0.10%
BCH $198.78 +2.43%
LINK $7.28 -0.23%
HYPE $65.65 +5.03%
AAVE $89.90 -4.19%
SUI $0.6945 +1.06%
XLM $0.1832 +6.04%
ZEC $398.76 +5.06%

Slow Fog CISO: Beware of the malicious npm package "@openclaw-ai/openclawai," which steals cryptocurrency wallet private keys and system credentials

2026-03-10 11:55:45
Collection

According to 23pds, the Chief Information Security Officer of Slow Fog Technology, an intelligence system has discovered a malicious npm package named "@openclaw-ai/openclawai" that is implementing a multi-layer attack.

This malicious package disguises itself as a legitimate command-line tool called OpenClaw Installer, aimed at stealing sensitive user information, including system credentials, cryptocurrency wallet private keys, browser data, SSH keys, and Apple Keychain database, among others.

app_icon
ChainCatcher Building the Web3 world with innovations.