Frequency
6
occurrences
First Seen
March 10, 2026
Last Seen
May 1, 2026
Related Threat Clusters
-
North Korean Malware Targets Crypto Developers via NPM Packages
A malicious npm package named @validate-sdk/v2, introduced through Anthropic’s Claude Opus AI model, has been linked to a breach in the open-source crypto trading project openpaw-graveyard. This malware, dubbed…
6 articles · Updated May 1, 2026 -
Malicious npm Package Disguises as OpenClaw to Deploy GhostClaw RAT
A rogue npm package named '@openclaw-ai/openclawai' has been identified as a malicious installer for a remote access trojan (RAT) known as GhostClaw. This malware targets software developers, stealing sensitive…
15 articles · Updated March 10, 2026 -
ClickFix Attack Wave Targets Windows Users with StealC Malware
A new social engineering campaign named ClickFix is targeting Windows users by presenting fake CAPTCHA verification pages. Victims are led to compromised websites that display fraudulent Cloudflare security checks,…
216 articles · Updated February 13, 2026
Recent Intelligence Reports
- Crypto trading tools under threat from Claude malware — Cryptopolitan · May 1, 2026
- Attacks via Terminal: Apple prevents command execution — Heise.De · March 27, 2026
- GhostClaw expands beyond npm: GitHub repositories and AI workflows deliver macOS infostealer — Mactech · March 20, 2026
- GhostClaw turns GitHub habits into a macOS malware pipeline — Appleinsider · March 20, 2026
- Fake OpenClaw npm Package Installs GhostClaw Malware — Esecurityplanet · March 11, 2026
- Devs looking for OpenClaw get served a GhostClaw RAT — Csoonline · March 10, 2026