ch0k1 on Nostr: Malicious NPM Package Posing as OpenClaw Installer Deploys RAT, Steals OS Data ...
Malicious NPM Package Posing as OpenClaw Installer Deploys RAT, Steals OS Data
https://thehackernews.com/2026/03/malicious-npm-package-posing-as.htmlCybersecurity researchers have discovered a malicious npm package that masquerades as an OpenClaw installer to deploy a remote access trojan (RAT) and steal sensitive data from compromised hosts.
The package, named "@openclaw-ai/openclawai," was uploaded to the registry by a user named "openclaw-ai" on March 3, 2026. It has been downloaded 178 times to date. The library is still available for download as of writing.
https://stacker.news/items/1451701Published at
2026-03-10 23:30:03 UTCEvent JSON
{
"id": "2a6ac8c69dbe72e432f29b1d5fc158cfa79836c7d2fb6352fba26754be2b526e",
"pubkey": "b4403b2415a020c20691bb18c51ada5acb64b71d2f60966cb3c78ba683542d4e",
"created_at": 1773185403,
"kind": 1,
"tags": [
[
"client",
"stacker.news"
]
],
"content": "Malicious NPM Package Posing as OpenClaw Installer Deploys RAT, Steals OS Data\nhttps://thehackernews.com/2026/03/malicious-npm-package-posing-as.html\n\nCybersecurity researchers have discovered a malicious npm package that masquerades as an OpenClaw installer to deploy a remote access trojan (RAT) and steal sensitive data from compromised hosts.\n\nThe package, named \"@openclaw-ai/openclawai,\" was uploaded to the registry by a user named \"openclaw-ai\" on March 3, 2026. It has been downloaded 178 times to date. The library is still available for download as of writing.\n\nhttps://stacker.news/items/1451701",
"sig": "00b0463aac7e7f4aeac8fa88f408144e0e31dcdbfaf2b4e06e2826f04c8105c35734008733de75f4edf306677d1bdee8af9bf846b9f16673e8830b89f6120556"
}