GhostClaw poses as OpenClaw in npm attack that can empty developer machines
VPN Central [Unofficial]
March 10, 2026
A malicious npm package has surfaced under the name @openclaw-ai/openclawai, and researchers say it impersonates an OpenClaw installer while stealing passwords, browser data, SSH keys, cloud credentials, crypto wallet data, and more from developer systems. JFrog Security Research published the findings on March 8 and said the package delivered a multi-stage infection chain plus a […]
The post GhostClaw poses as OpenClaw in npm attack that can empty developer machines appeared first on VPN Central.
Discussion in the ATmosphere