GhostClaw Mimic as OpenClaw to Steal Everything from Developers
ID: 59a07b59-21c0-5cca-81bd-1a3c183c5b28
STIX ID: report--59a07b59-21c0-5cca-81bd-1a3c183c5b28
Feed Name: cybersecurityNews.com
**Executive Summary:** A malicious npm package named @openclaw-ai/openclawai (tracked as GhostClaw / internally GhostLoader) disguised as an installer to socially engineer developer credentials, persist on macOS, Linux, and Windows systems, and deploy a multi-stage infostealer that harvests system passwords, macOS Keychain, cloud credentials (AWS/GCP/Azure), SSH keys, browser-saved credentials and cards, BIP-39 crypto seed phrases, and iMessage data; JFrog researchers attribute the discovery to active registry monitoring and recommend removal of the .npm_telemetry directory, shell cleanup, credential rotation, session revocation, and full system re-image where appropriate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
