Scan to download
BTC $59,544.57 -0.62%
ETH $1,586.06 +0.59%
BNB $553.85 +0.13%
XRP $1.04 -0.09%
SOL $74.26 +2.22%
TRX $0.3194 -0.63%
DOGE $0.0723 -0.93%
ADA $0.1443 -0.20%
BCH $199.90 +3.30%
LINK $7.29 -0.22%
HYPE $65.84 +5.52%
AAVE $89.79 -3.97%
SUI $0.6938 +0.78%
XLM $0.1823 +5.53%
ZEC $399.54 +4.53%
BTC $59,544.57 -0.62%
ETH $1,586.06 +0.59%
BNB $553.85 +0.13%
XRP $1.04 -0.09%
SOL $74.26 +2.22%
TRX $0.3194 -0.63%
DOGE $0.0723 -0.93%
ADA $0.1443 -0.20%
BCH $199.90 +3.30%
LINK $7.29 -0.22%
HYPE $65.84 +5.52%
AAVE $89.79 -3.97%
SUI $0.6938 +0.78%
XLM $0.1823 +5.53%
ZEC $399.54 +4.53%

Slow Fog CISO: Beware of the malicious npm package "@openclaw-ai/openclawai," which steals cryptocurrency wallet private keys and system credentials

2026-03-10 11:55:45
Collection

According to 23pds, the Chief Information Security Officer of Slow Fog Technology, an intelligence system has discovered a malicious npm package named "@openclaw-ai/openclawai" that is implementing a multi-layer attack.

This malicious package disguises itself as a legitimate command-line tool called OpenClaw Installer, aimed at stealing sensitive user information, including system credentials, cryptocurrency wallet private keys, browser data, SSH keys, and Apple Keychain database, among others.

app_icon
ChainCatcher Building the Web3 world with innovations.