The post Security analysts raise OpenClaw impersonator alarm as ai agents hit peak popularity appeared on BitcoinEthereumNews.com. A malicious npm package disguisedThe post Security analysts raise OpenClaw impersonator alarm as ai agents hit peak popularity appeared on BitcoinEthereumNews.com. A malicious npm package disguised

Security analysts raise OpenClaw impersonator alarm as ai agents hit peak popularity

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

A malicious npm package disguised as a legitimate AI tool to install the virally popular OpenClaw, but designed to steal system passwords and crypto wallets, has been identified by cybersecurity researchers. 

Following the discovery of this malware, experts are now pushing for a new trust infrastructure that will keep the intentions of users provable while AI agents act independently.

GhostLoader targets users on the popularity of OpenClaw and AI agents

Cybersecurity experts have found a malicious npm package designed to take advantage of the global rise in AI agent adoption. The package disguises itself as the installer for the popular OpenClaw AI tool, but it actually stealthily steals nearly every sensitive data point on a developer’s machine.

The npm package was found in a package.json file under the name @openclaw-ai/openclawai. Once it is installed, the script silently re-installs the package globally to ensure its binary is placed on the system PATH.

The first stage involves an obfuscated script named setup.js. To the user, this looks like a standard installation process with animated progress bars and realistic system logs. In reality, the script triggers a fake authorization prompt based on the user’s operating system, whether that’s macOS, Windows, or Linux, before the installation finishes.

Once the password is stolen, it is passed to a massive 11,700-line JavaScript bundle known as GhostLoader.

GhostLoader is a comprehensive info-stealer and Remote Access Trojan (RAT). It installs itself permanently in a hidden directory disguised as a telemetry service (.npm_telemetry). It also modifies shell configuration files such as .zshrc and .bashrc to ensure it restarts whenever the user opens a terminal.

The legitimate OpenClaw tool was originally developed in Austria as open-source software and is currently seeing massive adoption in Asia. Cryptopolitan recently reported that Baidu is adding the OpenClaw AI agent to its main smartphone search app, bringing the tool directly to a user base of approximately 700 million monthly active users. Baidu also plans to integrate OpenClaw into its e-commerce and digital services.

Shoppers use these AI agents to compare products and pay through services like Alipay without leaving the app, and GhostLoader specifically targets this by scanning for AI agent configurations.

It searches for credential stores associated with tools such as ZeroClaw, PicoClaw, and OpenClaw. If it finds these files, it can steal API keys and session states, allowing attackers to hijack the digital identity of the user’s AI agents.

Mastercard and Google jump on the agentic commerce bandwagon

With AI agent adoption on the rise, companies like Mastercard and Google have introduced a new trust infrastructure called Verifiable Intent.

Verifiable Intent creates a tamper-resistant, cryptographic record of exactly what a user authorized. Industry leaders have so far shown their support for the initiative. Google’s Stavan Parikh stated that a user’s intent must remain clear and provable as AI agents act independently.

Tom Adams, CTO at Adyen, stated that a verifiable, privacy-preserving way to confirm customer intent is now foundational for merchants. IBM’s Kirstin Kirtley Silva explained that Verifiable Intent makes user authorization simple and allows agents to act safely across different platforms.

The system uses Selective Disclosure, a technique that makes sure only the minimum necessary information is shared for a transaction.

If a malicious package like GhostLoader were to steal an agent’s configuration file in a Verifiable Intent system, the attacker wouldn’t be able to spend the user’s money because they would lack the specific, time-bound cryptographic proof of the user’s intent.

Cybersecurity firm CrowdStrike has warned that giving AI agents full access to business systems is inherently dangerous.

For those who have installed @openclaw-ai/openclawai, security analysts recommend checking your .zshrc and .bashrc files for any lines referencing npm_telemetry. Users are advised to remove the ~/.cache/.npm_telemetry/ directory and also change their system passwords, rotate all SSH keys, and move crypto funds to new wallets with new seed phrases.

Source: https://www.cryptopolitan.com/openclaw-alarm-ai-agents-peak-popularity/

Market Opportunity
LooksRare Logo
LooksRare Price(LOOKS)
$0.0005335
$0.0005335$0.0005335
+0.64%
USD
LooksRare (LOOKS) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Why Is Crypto Market Up Today? 5 Key Reasons Behind the Rally

Why Is Crypto Market Up Today? 5 Key Reasons Behind the Rally

The post Why Is Crypto Market Up Today? 5 Key Reasons Behind the Rally appeared on BitcoinEthereumNews.com. The crypto market is rallying today, with Bitcoin climbing
Share
BitcoinEthereumNews2026/03/11 04:47
‘Alien Earth’ Composer Jeff Russo Dives Into Score For FX Series

‘Alien Earth’ Composer Jeff Russo Dives Into Score For FX Series

The post ‘Alien Earth’ Composer Jeff Russo Dives Into Score For FX Series appeared on BitcoinEthereumNews.com. FX’s Alien: Earth — Pictured: Timothy Olyphant as Kirsh. Courtesy of Patrick Brown/FX The following contains certain spoilers for Alien: Earth! When it came time to marry picture and music for FX’s Alien: Earth, series creator Noah Hawley did what he’s done for close to 20 years: call up Jeff Russo. “[He] said, ‘I’m adapting the Alien IP, for television. What do you think, musically?’” Russo recalls over Zoom. “We started talking and I began writing music for it. It seemed like…not a foregone conclusion, but a conversation that was being had.” A founder of Tonic and a previous member of Low Stars, the composer has scored all of Hawley’s film and television projects since The Unusuals (2009). “Everything I’ve learned about making music for storytelling, I learned by doing with him,” Russo adds. “He really knows what he wants. And when you have a confident filmmaker that is also open to artistic collaboration, it’s the best of all the worlds.” The first small screen translation of the nearly 50-year-old franchise known for straddling horror, sci-fi, and action genres, Alien: Earth takes place two years before the events of the 1979 original and nearly six decades before Aliens. “We talk a lot about trying to figure out what the underlying property is making our audience feel,” Russo explains. “Trying to create a unique narrative and way of telling the story, but at the same time, making the audience feel that same feeling. In this case, there’s that feeling of dread. There’s that tense, eerie feeling created with such a deft hand in Alien. And then [came Aliens, which was] such a great action piece. So how are we going to take those two ideas and sort of mix them together, have that be something unique and different, while eliciting the…
Share
BitcoinEthereumNews2025/09/18 07:23
Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Share
BitcoinEthereumNews2025/09/17 23:45