BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

OpenClaw npm Package a Stealthy Data-Stealing Trojan

Sophisticated npm malware steals passwords, crypto wallets, and browser sessions from macOS users.

  • A malicious npm package posing as an OpenClaw AI installer has been deployed to steal passwords, cryptocurrency wallets, and sensitive data from macOS users.
  • The malware, nicknamed GhostLoader, employs sophisticated social engineering, including fake installation screens and keychain prompts, to harvest the victim’s system password.
  • Once installed, it deploys a full remote access trojan (RAT) capable of cloning live browser sessions, monitoring clipboards, and exfiltrating stolen data to command servers.

Cybersecurity researchers at JFrog uncovered a malicious npm package masquerading as an OpenClaw installer, which was uploaded to the registry on March 3, 2026, and has been downloaded 178 times. This package deploys a remote access trojan designed to steal system credentials, crypto wallets, and a vast array of sensitive information from compromised hosts.

- Advertisement -

The malicious logic triggers via a postinstall hook that globally re-installs the package. Consequently, the first-stage dropper script displays a convincing fake command-line interface with animated progress bars.

After the fake installation, a bogus iCloud Keychain prompt asks users for their system password. Meanwhile, the script retrieves an encrypted second-stage payload from the C2 server trackpipe[.]dev.

The second-stage JavaScript, a sophisticated information stealer and RAT framework, exfiltrates data from macOS Keychain, Chromium browsers, and cryptocurrency wallets. It also steals SSH keys, cloud credentials, and AI agent configurations, according to the JFrog report.

Security researcher Meitar Palas said “The attack is notable for its broad data collection, its use of social engineering to harvest the victim’s system password, and the sophistication of its persistence and C2 infrastructure.”

- Advertisement -

The malware also enters a persistent daemon mode to monitor the clipboard for private keys and crypto addresses. Furthermore, it can clone a victim’s live browser session, giving attackers full authenticated access.

Finally, the collected data is compressed and exfiltrated through multiple channels. The package combines social engineering, encrypted payloads, and a persistent RAT into a single dangerous threat.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

MSTR Becomes Largest Bitcoin Holder With $2.54B Purchase

Strategy made its largest 2026 Bitcoin purchase, acquiring 34,164 BTC for $2.54 billion at...

Crypto ETF Inflows Hit $1.4B on Bitcoin Breakout, Ceasefire Hopes

Cryptocurrency ETPs attracted $1.4 billion in weekly inflows, the second-largest week since January 2026.Bitcoin...

ZionSiphon Malware Targets Israeli Water Systems

Analysts discovered ZionSiphon, malware designed to attack Israeli water infrastructure with sabotage features.The tool...

Grant Cardone Bets $500M on Bitcoin, Aims for 10,000 BTC

Billionaire investor Grant Cardone intends to purchase $500 million in Bitcoin this year and...

Surfshark Launches Dausos, a Proprietary VPN Protocol With Dedicated Tunnels and Post-Quantum Encryption

Surfshark's new Dausos protocol assigns each user a dedicated server-side tunnel instead of sharing...

Must Read

12 Hosting Providers To Buy VPS With Bitcoin: An Expert Guide for 2026

You need a VPS. You want to pay with Bitcoin. Simple enough, right?Not quite. The market for crypto VPS = VPS hosting that accepts...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading