Huoxun Finance reported on March 10 that SlowMist issued a warning about a malicious npm package called "@openclaw-ai/openclawai". This package masquerades as a legitimate command-line tool called OpenClawInstalle, deploying a multi-layered attack chain to steal system credentials, encrypted wallet private keys, browser data, SSH keys, Apple Keychain databases, and other information.
SlowMist: Beware of a malicious npm package named "@openclaw-ai/openclawai"
2026-03-10 04:32:02
Share
Disclaimer: This article is copyrighted by the original author and does not represent MyToken’s views and positions. If you have any questions regarding content or copyright, please contact us.(www.mytokencap.com)contact
About MyToken:https://www.mytokencap.com/en/aboutusArticle Link:https://www.mytokencap.com/en/choicenews/3079133.html