Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials
A malicious npm package named "@openclaw-ai/openclawai" masquerading as an OpenClaw installer was discovered deploying a remote access trojan (RAT) and stealing macOS credentials. Uploaded on March 3, 2026, by user "openclaw-ai," the package had been downloaded 178 times and remains available on the registry. This supply chain attack targets developers through dependency poisoning via a counterfeit package.
Summary
A malicious npm package named "@openclaw-ai/openclawai" masquerading as an OpenClaw installer was discovered deploying a remote access trojan (RAT) and stealing macOS credentials. Uploaded on March 3, 2026, by user "openclaw-ai," the package had been downloaded 178 times and remains available on the registry. This supply chain attack targets developers through dependency poisoning via a counterfeit package.
Indicators of Compromise
- malware — @openclaw-ai/openclawai
- email — openclaw-ai