• bitcoinBitcoin (BTC) $ 80,840.00
  • ethereumEthereum (ETH) $ 2,326.43
  • tetherTether (USDT) $ 0.999861
  • bnbBNB (BNB) $ 647.70
  • xrpXRP (XRP) $ 1.41
  • usd-coinUSDC (USDC) $ 0.999547
  • solanaSolana (SOL) $ 89.17
  • tronTRON (TRX) $ 0.346761
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • dogecoinDogecoin (DOGE) $ 0.111010
  • whitebitWhiteBIT Coin (WBT) $ 59.09
  • usdsUSDS (USDS) $ 0.999659
  • hyperliquidHyperliquid (HYPE) $ 42.71
  • cardanoCardano (ADA) $ 0.267183
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 10.35
  • zcashZcash (ZEC) $ 568.30
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • bitcoin-cashBitcoin Cash (BCH) $ 458.15
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 413.33
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • chainlinkChainlink (LINK) $ 9.99
  • the-open-networkToncoin (TON) $ 2.56
  • canton-networkCanton (CC) $ 0.146153
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.160600
  • memecoreMemeCore (M) $ 3.97
  • usd1-wlfiUSD1 (USD1) $ 0.999695
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999432
  • litecoinLitecoin (LTC) $ 56.92
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • avalanche-2Avalanche (AVAX) $ 9.57
  • ethena-usdeEthena USDe (USDE) $ 0.999316
  • suiSui (SUI) $ 0.990567
  • wethWETH (WETH) $ 2,268.37
  • hedera-hashgraphHedera (HBAR) $ 0.090896
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007255
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 0.999754
  • crypto-com-chainCronos (CRO) $ 0.070482
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • bittensorBittensor (TAO) $ 307.70
  • tether-goldTether Gold (XAUT) $ 4,723.06
  • global-dollarGlobal Dollar (USDG) $ 0.999882
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.072361
  • pax-goldPAX Gold (PAXG) $ 4,727.58
  • polkadotPolkadot (DOT) $ 1.32
  • mantleMantle (MNT) $ 0.667413
  • uniswapUniswap (UNI) $ 3.46
  • nearNEAR Protocol (NEAR) $ 1.48
  • pi-networkPi Network (PI) $ 0.179903
  • skySky (SKY) $ 0.079952
  • okbOKB (OKB) $ 86.91
  • falcon-financeFalcon USD (USDF) $ 0.998561
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pepePepe (PEPE) $ 0.000004
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • aster-2Aster (ASTER) $ 0.672698
  • internet-computerInternet Computer (ICP) $ 3.08
  • ondo-financeOndo (ONDO) $ 0.343934
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 2.16
  • usddUSDD (USDD) $ 0.999820
  • ethereum-classicEthereum Classic (ETC) $ 9.26
  • aaveAave (AAVE) $ 93.62
  • morphoMorpho (MORPHO) $ 2.15
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bfusdBFUSD (BFUSD) $ 0.999299
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • kucoin-sharesKuCoin (KCS) $ 8.41
  • algorandAlgorand (ALGO) $ 0.126569
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • ethenaEthena (ENA) $ 0.122318
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.099839
  • render-tokenRender (RENDER) $ 2.00
  • united-stablesUnited Stables (U) $ 1.00
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.07
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • quant-networkQuant (QNT) $ 70.19
  • kaspaKaspa (KAS) $ 0.036535
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.24
  • cosmosCosmos Hub (ATOM) $ 1.92
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.77
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.893623
  • worldcoin-wldWorldcoin (WLD) $ 0.257087
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • filecoinFilecoin (FIL) $ 1.09
  • aptosAptos (APT) $ 1.02
  • wbnbWrapped BNB (WBNB) $ 759.61
  • gatechain-tokenGate (GT) $ 7.25
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • siren-2Siren (SIREN) $ 1.15
  • arbitrumArbitrum (ARB) $ 0.127501
  • stable-2​​Stable (STABLE) $ 0.032748
  • justJUST (JST) $ 0.085432
  • pump-funPump.fun (PUMP) $ 0.001999
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • jupiter-exchange-solanaJupiter (JUP) $ 0.202298
  • flare-networksFlare (FLR) $ 0.007794
  • vechainVeChain (VET) $ 0.007701
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • dashDash (DASH) $ 52.40
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010487
  • skyaiSkyAI (SKYAI) $ 0.623626
  • usdtbUSDtb (USDTB) $ 0.999693
  • beldexBeldex (BDX) $ 0.079687
  • ousgOUSG (OUSG) $ 115.16
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • bonkBonk (BONK) $ 0.000007
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • hash-2Provenance Blockchain (HASH) $ 0.011423
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.910069
  • xdce-crowd-saleXDC Network (XDC) $ 0.029907
  • venice-tokenVenice Token (VVV) $ 12.91
  • clbtcclBTC (CLBTC) $ 76,920.00
  • ghoGHO (GHO) $ 0.999551
  • usual-usdUsual USD (USD0) $ 0.998286
  • dexeDeXe (DEXE) $ 11.79
  • official-trumpOfficial Trump (TRUMP) $ 2.36
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000098
  • megausdMegaUSD (USDM) $ 0.999761
  • yldsYLDS (YLDS) $ 0.999916
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • midnight-3Midnight (NIGHT) $ 0.031329
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.226488
  • tbtctBTC (TBTC) $ 70,942.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.55
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • a7a5A7A5 (A7A5) $ 0.012742
  • true-usdTrueUSD (TUSD) $ 0.998709
  • blockstackStacks (STX) $ 0.255492
  • edgexedgeX (EDGE) $ 1.33
  • chilizChiliz (CHZ) $ 0.043838
  • euro-coinEURC (EURC) $ 1.18
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • aerodrome-financeAerodrome Finance (AERO) $ 0.449149
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • sei-networkSei (SEI) $ 0.061028
  • tezosTezos (XTZ) $ 0.377198
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • adi-tokenADI (ADI) $ 3.93
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999011
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • spx6900SPX6900 (SPX) $ 0.429014
  • usdgoUSDGO (USDGO) $ 1.00
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • monadMonad (MON) $ 0.032839
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • injective-protocolInjective (INJ) $ 3.87
  • sun-tokenSun Token (SUN) $ 0.020135
  • usxUSX (USX) $ 0.999728
  • curve-dao-tokenCurve DAO (CRV) $ 0.244881
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • layerzeroLayerZero (ZRO) $ 1.47
  • humanityHumanity (H) $ 0.200334
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • kite-2Kite (KITE) $ 0.159403
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • ether-fiEther.fi (ETHFI) $ 0.430863
  • kinesis-goldKinesis Gold (KAU) $ 150.57
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.359098
  • decredDecred (DCR) $ 20.30
  • celestiaCelestia (TIA) $ 0.383653
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • gnosisGnosis (GNO) $ 132.52
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • build-onBUILDon (B) $ 0.345013
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • labLAB (LAB) $ 4.46
  • unibaseUnibase (UB) $ 0.137187
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • flokiFLOKI (FLOKI) $ 0.000035
  • conflux-tokenConflux (CFX) $ 0.063961
  • lido-daoLido DAO (LDO) $ 0.388257
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • hastra-primePRIME (PRIME) $ 1.04
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • bitcoin-svBitcoin SV (BSV) $ 16.21
  • doublezeroDoubleZero (2Z) $ 0.093545
  • zebec-networkZebec Network (ZBCN) $ 0.003296
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • bittorrentBitTorrent (BTT) $ 0.00000033
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

GhostClaw steals crypto wallet data from devs

0 25

GhostClaw steals crypto wallet data from devs

A new malware dubbed GhostClaw is targeting crypto wallets on macOS machines. The fake OpenClaw installer captures private keys, wallet access, and other sensitive data after installation.

The fake package was uploaded by a user named ‘openclaw-ai’ on March 3. It remained on the npm registry for a week and infected 178 developers before removal on March 10.

@openclaw-ai/openclawai posed as a legitimate OpenClaw CLI tool but instead ran a multi-stage attack.

The malware collected sensitive data from developers. It extracted crypto wallets, macOS Keychain passwords, cloud credentials, SSH keys, and AI agent configs. The extracted data connects hackers to cloud platforms, codebases, and crypto.

GhostClaw scans the clipboard for crypto data every three seconds

The malware monitors the clipboard every three seconds to capture crypto data. This includes private keys, seed phrases, public keys, and other sensitive data related to crypto wallets and transactions.

Once the developer runs the ‘npm install’ command, a hidden script installs the GhostClaw package globally. The tool runs an obfuscated setup file on developers’ machines to avoid detection.

A fake OpenClaw CLI installer then appears on the screen. It prompts the victim to enter their macOS password through a Keychain request. The malware verifies the password using a native system tool. After that, it downloads a second JavaScript payload from a remote C2 server. The payload, called GhostLoader, acts as a data stealer and remote access tool.

See also Cardano Price Analysis: Cardano bulls fade off as coin breaks below $1.40

Data theft begins after the second payload download. GhostLoader does the heavy work. It scans Chromium browsers, Macintosh operating system (macOS) Keychain, and system storage for crypto wallet data. It also monitors the clipboard almost continuously to capture sensitive crypto data.

The malware even clones browser sessions. This gives hackers direct access to logged-in crypto wallets and other related services. Moreover, the malicious tool steals API tokens that connect devs to AI platforms like OpenAI and Anthropic.

The stolen data is then sent to threat actors via Telegram, GoFile, and command servers. The malware can also run numerous commands, deploy more payloads, and open new remote access channels.

OpenClaw community hit with fake CLAW tokens airdrop

Another malicious campaign that relies on OpenClaw’s hype spread on GitHub. The malware, which was discovered by cybersecurity researchers from OX Security, aims to contact devs directly and steal crypto data.

Attackers create issue-threads in GitHub repositories and tag potential victims. Then they falsely state that chosen devs are eligible to receive $5,000 in CLAW tokens.

The messages then lead recipient devs to a fake website that looks exactly like openclaw[.]ai. The phishing website sends a crypto wallet connection request that starts harmful actions when accepted by the victim. Linking a wallet to the site can lead to instant theft of crypto funds, warns OX Security researchers.

See also Tesla’s AI-powered humanoid robots redefine the future of automation

Further analysis of the attack reveals that the phishing setup uses a redirect chain to token-claw[.]xyz and a command server at watery-compost[.]today. A JavaScript file with malicious code then steals crypto wallet addresses and transactions and sends them to the hacker.

OX Security found a wallet address tied to the threat actor that might hold stolen crypto. The malicious code has features to monitor user actions and remove data from local storage. This makes malware detection and analysis harder.

The attackers likely focus on users who have interacted with OpenClaw related repositories to increase their chances of crypto theft.

Both attacks rely on social engineering as an entry point to victims’ crypto wallets. Users should not link crypto wallets to unknown sites and should be wary of unsolicited token offers on GitHub.

Source

Leave A Reply

Your email address will not be published.