The post GhostClaw steals crypto wallet data from devs appeared on BitcoinEthereumNews.com. A new malware dubbed GhostClaw is targeting crypto wallets on macOSThe post GhostClaw steals crypto wallet data from devs appeared on BitcoinEthereumNews.com. A new malware dubbed GhostClaw is targeting crypto wallets on macOS

GhostClaw steals crypto wallet data from devs

2026/03/23 07:48
3 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

A new malware dubbed GhostClaw is targeting crypto wallets on macOS machines. The fake OpenClaw installer captures private keys, wallet access, and other sensitive data after installation.

The fake package was uploaded by a user named ‘openclaw-ai’ on March 3. It remained on the npm registry for a week and infected 178 developers before removal on March 10.

@openclaw-ai/openclawai posed as a legitimate OpenClaw CLI tool but instead ran a multi-stage attack.

The malware collected sensitive data from developers. It extracted crypto wallets, macOS Keychain passwords, cloud credentials, SSH keys, and AI agent configs. The extracted data connects hackers to cloud platforms, codebases, and crypto.

GhostClaw scans the clipboard for crypto data every three seconds

The malware monitors the clipboard every three seconds to capture crypto data. This includes private keys, seed phrases, public keys, and other sensitive data related to crypto wallets and transactions.

Once the developer runs the ‘npm install’ command, a hidden script installs the GhostClaw package globally. The tool runs an obfuscated setup file on developers’ machines to avoid detection.

A fake OpenClaw CLI installer then appears on the screen. It prompts the victim to enter their macOS password through a Keychain request. The malware verifies the password using a native system tool. After that, it downloads a second JavaScript payload from a remote C2 server. The payload, called GhostLoader, acts as a data stealer and remote access tool.

Data theft begins after the second payload download. GhostLoader does the heavy work. It scans Chromium browsers, Macintosh operating system (macOS) Keychain, and system storage for crypto wallet data. It also monitors the clipboard almost continuously to capture sensitive crypto data.

The malware even clones browser sessions. This gives hackers direct access to logged-in crypto wallets and other related services. Moreover, the malicious tool steals API tokens that connect devs to AI platforms like OpenAI and Anthropic.

The stolen data is then sent to threat actors via Telegram, GoFile, and command servers. The malware can also run numerous commands, deploy more payloads, and open new remote access channels.

Another malicious campaign that relies on OpenClaw’s hype spread on GitHub. The malware, which was discovered by cybersecurity researchers from OX Security, aims to contact devs directly and steal crypto data.

Attackers create issue-threads in GitHub repositories and tag potential victims. Then they falsely state that chosen devs are eligible to receive $5,000 in CLAW tokens.

The messages then lead recipient devs to a fake website that looks exactly like openclaw[.]ai. The phishing website sends a crypto wallet connection request that starts harmful actions when accepted by the victim. Linking a wallet to the site can lead to instant theft of crypto funds, warns OX Security researchers.

Further analysis of the attack reveals that the phishing setup uses a redirect chain to token-claw[.]xyz and a command server at watery-compost[.]today. A JavaScript file with malicious code then steals crypto wallet addresses and transactions and sends them to the hacker.

OX Security found a wallet address tied to the threat actor that might hold stolen crypto. The malicious code has features to monitor user actions and remove data from local storage. This makes malware detection and analysis harder.

The attackers likely focus on users who have interacted with OpenClaw related repositories to increase their chances of crypto theft.

Both attacks rely on social engineering as an entry point to victims’ crypto wallets. Users should not link crypto wallets to unknown sites and should be wary of unsolicited token offers on GitHub.

Source: https://www.cryptopolitan.com/ghostclaw-steals-crypto-wallet-data-devs/

Opportunità di mercato
Logo Cloud
Valore Cloud (CLOUD)
$0,0413
$0,0413$0,0413
+8,51%
USD
Grafico dei prezzi in tempo reale di Cloud (CLOUD)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

Supported by hike speculation and PMIs – Danske Bank

Supported by hike speculation and PMIs – Danske Bank

The post Supported by hike speculation and PMIs – Danske Bank appeared on BitcoinEthereumNews.com. Danske Research Team points out that the Euro was the second-
Condividi
BitcoinEthereumNews2026/03/23 15:59
The geopolitics of anti-corruption as global advisory firms face debarment in the Horn of Africa

The geopolitics of anti-corruption as global advisory firms face debarment in the Horn of Africa

The World Bank’s debarment of PwC and EY for fraud in Ethiopia and Somalia has lifted the veil on the fragility of the Western development model, creating a strategic
Condividi
Theexchange2026/03/23 16:33
Health Insurers To Cover Covid Vaccines Despite RFK, Jr. Moves

Health Insurers To Cover Covid Vaccines Despite RFK, Jr. Moves

The post Health Insurers To Cover Covid Vaccines Despite RFK, Jr. Moves appeared on BitcoinEthereumNews.com. The nation’s biggest health insurance companies will continue to cover vaccinations – including those against Covid-19 and seasonal flu – previously recommended by a federal advisory committee, America’s Health Insurance Plans said Wednesday, Sept. 17, 2025. In this photo is a free flu and Covid-19 vaccine shots available sign, CVS, Queens, New York. (Photo by: Lindsey Nicholson/Universal Images Group via Getty Images) UCG/Universal Images Group via Getty Images The nation’s biggest health insurance companies will continue to cover vaccinations – including those against Covid-19 and seasonal flu – previously recommended by a federal advisory committee. The announcement by America’s Health Insurance Plans (AHIP), which includes CVS Health’s Aetna, Humana, Cigna, Centene and an array of Blue Cross and Blue Shield plans as members, comes ahead of the first meeting of the reconstituted Advisory Committee on Immunization Practices, which now has new members chosen by U.S. Health and Human Services Secretary Robert F. Kennedy Jr., a vaccine critic. “Health plans are committed to maintaining and ensuring affordable access to vaccines,” AHIP said in a statement Wednesday. “Health plan coverage decisions for immunizations are grounded in each plan’s ongoing, rigorous review of scientific and clinical evidence, and continual evaluation of multiple sources of data.” The move by AHIP is good news for millions of Americans at a time of year when they flock to drugstores, pharmacies, physician’s offices and outpatient clinics to get their seasonal flu and Covid shots. Kennedy’s changes to U.S. vaccine policy have created confusion across the country over whether certain vaccines long covered by insurance would continue to be. AHIP has now provided some clarity for millions of Americans. “Health plans will continue to cover all ACIP-recommended immunizations that were recommended as of September 1, 2025, including updated formulations of the COVID-19 and influenza vaccines, with no cost-sharing…
Condividi
BitcoinEthereumNews2025/09/18 03:11