Wu Shuo learned that according to 23pds, the Chief Information Security Officer of SlowMist Technology, citing MistEye intelligence, caution is needed regarding a malicious npm package named "@openclaw-ai/openclawai." This package disguises itself as a legitimate command-line tool called "OpenClaw Installer," deploying a multi-layer attack chain, suspected of stealing system credentials, encrypt wallet private keys, browser data, SSH keys, and Apple Keychain database and other sensitive information.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin