[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBAM6qb9yOYAjK6J2rz3tf8rjz6kd59N-EaqkNDp2DUE":3},{"article":4,"iocs":36,"watch_terms":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":12,"published_at":13,"ingested_at":14,"relevance_score":10,"entities":15,"category_id":16,"category":17,"article_tags":20},"b9f40192-f66f-4011-b04e-d8907b16458f","Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials","malicious-npm-package-posing-as-openclaw-installer-deploys-rat-steals-macos-cred","Cybersecurity researchers have discovered a malicious npm package that masquerades as an OpenClaw installer to deploy a remote access trojan (RAT) and steal sensitive data from compromised hosts. The package, named \"@openclaw-ai\u002Fopenclawai,\" was uploaded to the registry by a user named \"openclaw-ai\" on March 3, 2026. It has been downloaded 178 times to date. The library is still available for","A malicious npm package named \"@openclaw-ai\u002Fopenclawai\" masquerading as an OpenClaw installer was discovered deploying a remote access trojan (RAT) and stealing macOS credentials. Uploaded on March 3, 2026, by user \"openclaw-ai,\" the package had been downloaded 178 times and remains available on the registry. This supply chain attack targets developers through dependency poisoning via a counterfeit package.",null,"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Fmalicious-npm-package-posing-as.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjNWahQ89p408qBpZO2cmP-m44fNG_BRHT34hjfmDGn2WhALZRls9d94ap8uK0ZYXj1JjAgxdDogTHv_1PHloweK3RtglJheCsgulTB0-KrYOgUFI3Gvp4FJiPaV33FVa8I5bl-v92O1IephSEiV_FMU010of5pnmgMQ0ZmBuvY4yC0Bl0ndth42P924uxR\u002Fs1600\u002Fopenclaw.jpg","2026-03-09T18:31:00+00:00","2026-03-14T09:41:13.354083+00:00",[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":16,"icon":10,"name":18,"slug":19},"Malware","malware",[21,26,31],{"category":22},{"id":23,"icon":10,"name":24,"slug":25},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":27},{"id":28,"icon":10,"name":29,"slug":30},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":32},{"id":33,"icon":10,"name":34,"slug":35},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[37,40],{"type":19,"value":38,"context":39},"@openclaw-ai\u002Fopenclawai","Malicious npm package deploying RAT and stealing macOS credentials",{"type":41,"value":42,"context":43},"email","openclaw-ai","npm registry user account used to upload malicious package",[]]