Back to Feed
MalwareMar 9, 2026

Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials

A malicious npm package named "@openclaw-ai/openclawai" masquerading as an OpenClaw installer was discovered deploying a remote access trojan (RAT) and stealing macOS credentials. Uploaded on March 3, 2026, by user "openclaw-ai," the package had been downloaded 178 times and remains available on the registry. This supply chain attack targets developers through dependency poisoning via a counterfeit package.

Summary

A malicious npm package named "@openclaw-ai/openclawai" masquerading as an OpenClaw installer was discovered deploying a remote access trojan (RAT) and stealing macOS credentials. Uploaded on March 3, 2026, by user "openclaw-ai," the package had been downloaded 178 times and remains available on the registry. This supply chain attack targets developers through dependency poisoning via a counterfeit package.

Indicators of Compromise

  • malware — @openclaw-ai/openclawai
  • email — openclaw-ai