Skip to content
Malicious npm Package Disguises as OpenClaw to Deploy GhostClaw RAT

Malicious npm Package Disguises as OpenClaw to Deploy GhostClaw RAT

First seen 10 Mar 2026, 11:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 26, 2026 at 21:46 UTC

A rogue npm package named '@openclaw-ai/openclawai' has been identified as a malicious installer for a remote access trojan (RAT) known as GhostClaw. This malware targets software developers, stealing sensitive information such as system credentials, browser data, cryptocurrency wallets, and SSH keys. The attack employs a multi-stage infection chain, posing a significant risk to affected users.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 197d ago How this analysis works

Timeline

2026-03-10
Malicious npm package '@openclaw-ai/openclawai' discovered
2026-03-10
JFrog research reports on GhostClaw RAT deployment
Date unknown
Attack targets software developers with fake OpenClaw installer

More articles in this cluster (15)

Following this threat?

Track GhostClaw in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed