HomeSecurityMalicious npm package impersonates OpenClaw and deploys RAT

Malicious npm package impersonates OpenClaw and deploys RAT

Cybersecurity researchers have discovered a malicious npm package that pretends to be an OpenClaw installer to deploy a remote access trojan (RAT) and steal sensitive data from compromised computers.

See also: North Koreans published 26 malicious npm packages for RAT distribution

malicious npm package

The npm package, named “@openclaw-ai/openclawai,” was uploaded to the registry by a user named “openclaw-ai” on March 3, 2026. It has been downloaded 178 times. The library is still available for download as of now.

JFrog, which discovered the package, said it is designed to steal system credentials, browser data, cryptocurrency wallets, SSH keys, Apple Keychain databases, and iMessage history, as well as install a persistent RAT with remote access capabilities, SOCKS5 proxy, and live browser session cloning.

The malicious logic is activated via a postinstall hook, which reinstalls the package globally using the command: “ npm i -g @openclaw-ai/openclawai .” Once the installation is complete, the OpenClaw binary points to “ scripts/setup.js ” via the “ bin ” attribute in the “ package.json ” file.

It is worth noting that the “bin” field is used to specify executable files that should be added to the user’s PATH when the package is installed. This, in turn, turns the package into a globally accessible command line tool.

The “setup.js” file acts as the first stage of the dropper that, when executed, displays a convincing fake command-line interface with moving progress bars to give the impression that OpenClaw is being installed on the computer. After the installation is supposedly complete, the script displays a fake iCloud Keychain authorization window, asking users to enter their system password.

See also: NPM's update on strengthening the supply chain

Malicious npm package impersonates OpenClaw and deploys RAT

At the same time, the script retrieves an encrypted second-stage JavaScript payload from the C2 server (“trackpipe[.]dev”), which is then decoded, written to a temporary file, and executed as a detached process to continue operating in the background. The temporary file is deleted after 60 seconds to cover up the activity.

The second-stage JavaScript, with approximately 11,700 lines, is a full-fledged information-stealing framework and RAT capable of persistence, data collection, browser decryption, C2 communication, SOCKS5 proxying, and live browser cloning. It is also equipped to steal a wide range of data:

  • macOS Keychain, including both the local login.keychain-db and all iCloud Keychain databases
  • Credentials, cookies, credit cards, and autofill data from all Chromium-based browsers, including Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera, Yandex, and Comet
  • Data from desktop wallet apps and browser extensions
  • Cryptocurrency wallet seed phrases
  • Developer and cloud credentials for AWS, Microsoft Azure, Google Cloud, Kubernetes, Docker, and GitHub
  • Artificial Intelligence (AI) Agent Configurations
  • FDA-protected data, including Apple Notes, iMessage history, Safari browsing history, Mail account configurations, and Apple account information

In the final stage, the collected data is compressed into a tar.gz and exported through multiple channels, including directly to the C2 server, the Telegram Bot API, and GoFile.io.

See also: Lazarus campaign plants malicious npm and PyPI packages

OpenClaw AI assistant tool cybersecurity threats

The malware enters a persistent daemon mode that allows it to monitor the clipboard contents every three seconds and transmit any data that matches one of nine predefined patterns.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS