OpenClaw npm Malware: Fake Package Deploys GhostLoader RAT
A malicious npm package called @openclaw-ai/openclawai sat on the npm registry for seven days, from March 3 to March 10, and infected 178 machines before npm pulled it. JFrog security researchers discovered the package and named this OpenClaw npm mal...
yixn.hashnode.dev2 min read