Scan to download
BTC $79,089.00 -2.80%
ETH $2,220.76 -3.25%
BNB $673.41 -1.04%
XRP $1.44 -4.49%
SOL $89.27 -3.67%
TRX $0.3514 -0.82%
DOGE $0.1129 -2.38%
ADA $0.2607 -4.41%
BCH $425.10 -2.79%
LINK $10.02 -5.19%
HYPE $44.10 -0.24%
AAVE $92.66 -7.13%
SUI $1.09 -8.63%
XLM $0.1543 -6.14%
ZEC $516.78 -5.52%
BTC $79,089.00 -2.80%
ETH $2,220.76 -3.25%
BNB $673.41 -1.04%
XRP $1.44 -4.49%
SOL $89.27 -3.67%
TRX $0.3514 -0.82%
DOGE $0.1129 -2.38%
ADA $0.2607 -4.41%
BCH $425.10 -2.79%
LINK $10.02 -5.19%
HYPE $44.10 -0.24%
AAVE $92.66 -7.13%
SUI $1.09 -8.63%
XLM $0.1543 -6.14%
ZEC $516.78 -5.52%

Slow Fog CISO: Beware of the malicious npm package "@openclaw-ai/openclawai," which steals cryptocurrency wallet private keys and system credentials

2026-03-10 11:55:45
Collection

According to 23pds, the Chief Information Security Officer of Slow Fog Technology, an intelligence system has discovered a malicious npm package named "@openclaw-ai/openclawai" that is implementing a multi-layer attack.

This malicious package disguises itself as a legitimate command-line tool called OpenClaw Installer, aimed at stealing sensitive user information, including system credentials, cryptocurrency wallet private keys, browser data, SSH keys, and Apple Keychain database, among others.

app_icon
ChainCatcher Building the Web3 world with innovations.