External Publication
Visit Post

GhostClaw poses as OpenClaw in npm attack that can empty developer machines

VPN Central [Unofficial] March 10, 2026
Source
A malicious npm package has surfaced under the name @openclaw-ai/openclawai, and researchers say it impersonates an OpenClaw installer while stealing passwords, browser data, SSH keys, cloud credentials, crypto wallet data, and more from developer systems. JFrog Security Research published the findings on March 8 and said the package delivered a multi-stage infection chain plus a […] The post GhostClaw poses as OpenClaw in npm attack that can empty developer machines appeared first on VPN Central.

Discussion in the ATmosphere

Loading comments...