Deceptive “DeepSeek-Claw” Skill Hijacks OpenClaw Agents to Steal Credentials
ID: 9677c363-829b-5eb6-8b64-c903fb074dcc
STIX ID: report--9677c363-829b-5eb6-8b64-c903fb074dcc
Feed Name: securityonline.info
Threat Score
**Executive Summary:** Zscaler ThreatLabz uncovered a deceptive supply-chain campaign in which a malicious OpenClaw skill ('DeepSeek-Claw') delivers Remcos RAT on Windows (via MSI and DLL sideloading) and GhostLoader on macOS/Linux (via obfuscated Node.js payloads and droppers), using terminal social engineering and npm lifecycle script abuse to obtain credentials and steal Keychain data, SSH keys, cloud API tokens, and cryptocurrency wallets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
