Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials

Researchers studying cybersecurity have found a malicious npm package that poses as an OpenClaw installer in order to install a remote access trojan (RAT) and steal private information from compromised machines.

On March 3, 2026, a person going by the moniker “openclaw-ai” uploaded the package, titled “.openclaw-ai/openclawai,” to the registry. To date, 178 people have downloaded it. As of this writing, you can still download the library.

According to JFrog, which found the program, it is intended to install a persistent RAT with remote access capabilities, SOCKS5 proxy, and live browser session cloning, as well as steal system passwords, browser data, cryptocurrency wallets, SSH keys, Apple Keychain databases, and iMessage histories.

According to security researcher Meitar Palas, the assault is noteworthy for its extensive data collecting, its sophisticated persistence read more about Malicious npm Package Posing as OpenClaw Installer Deploys RAT Steals macOS Credentials.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *