Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials

2026-03-10T01:24:16Ze391050eb64bb83a4813a70f579b34ffb2b130cd7e616e747dd324252950def3
AI-powered-malwareAirDropAsyncRATBruteEntryDindoorLumma-StealerMimikatzMuddyWaterPeerTimeRATTernDoorTransparent-TribeUNC4899VOID#GEISTWindows-Terminal-social-engineering','CISA-KEV','active-exploit'XWormXeno-RATchrome-extensioncode-injectioncredential-theftmacOSnpmsupply-chaintrojanweb-server-exploits

What happened

A range of active and emerging threats reported: a malicious npm package (@openclaw-ai/openclawai) posing as an OpenClaw installer deploys a RAT and steals macOS credentials; UNC4899 used AirDrop to deliver a trojanized file enabling a cloud compromise of a crypto firm; Chrome extensions turned malicious after ownership transfer enabling code injection and data theft; multi-stage campaigns (VOID#GEIST) are delivering XWorm, AsyncRAT and Xeno RAT; Transparent Tribe is using AI to mass-produce implants; MuddyWater/GhostDoor activity includes a new Dindoor backdoor; China-linked actors are usingT

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
e391050eb64bb83a4813a70f579b34ffb2b130cd7e616e747dd324252950def3
Enrichment time
2026-03-10T01:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials · Baitaphish