GhostClaw Mimic as OpenClaw to Steal Everything from Developers

A dangerous malware campaign targeting software developers has surfaced, with a rogue npm package posing as a trusted developer tool to silently drain credentials, crypto wallets, SSH keys, browser sessions, and even iMessage conversations. The package, published under the name @openclaw-ai/openclawai, disguises itself as a legitimate command-line installer called “OpenClaw Installer” while deploying a deeply hidden […]

The post GhostClaw Mimic as OpenClaw to Steal Everything from Developers appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: