Beware of the malicious Npm package "@openclaw-ai/openclawai" which steals cryptocurrency wallet private keys and system credentials.

Mars Finance reports that according to 23pds, Chief Information Security Officer of SlowMist Technology, the intelligence system has detected a malicious npm package named “@openclaw-ai/openclawai” conducting multi-layered attacks. The malicious package disguises itself as a legitimate command-line tool called OpenClaw Installer, aiming to steal users’ sensitive information, including system credentials, crypto wallet private keys, browser data, SSH keys, and Apple Keychain database.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin