Web3 Security Stack Highlights Threat from Malicious NPM Package

TheNewsCryptoPublished on 2026-03-10Last updated on 2026-03-10

Abstract

Web3 Antivirus has identified a malicious NPM package disguised as an OpenClaw installer that deploys a Remote Access Trojan (RAT) targeting macOS users. The package, once installed, launches a fake CLI installer and prompts for the Keychain password. If provided, it steals sensitive data including seed phrases, browser credentials, wallet information, and SSH keys, sending them to the attacker’s server. Previously, Web3 Antivirus warned about legitimate Chrome extensions—QuickLens and ShotBird—that turned malicious after ownership transfers. These were used to inject malicious scripts and steal user data, including exchange session details and wallet credentials. Looking ahead to 2026, key Web3 security threats include smart contract exploits (due to logic errors and access control issues), phishing, social engineering, wallet drainers, and oracle manipulation. The primary goals of these attacks are data theft and fund draining.

Web3 Antivirus, or Web3 security stack, has highlighted a threat from a malicious NPM package. It earlier flagged a threat from a legitimate Chrome extension. Notably, smart contract exploits and phishing & social engineering are some of the top Web3 security threats to lookout for in 2026.

Web3 Security Issue Flagged

Web3 Antivirus has published a post on X to inform the community that a malicious NPM package was caught deploying a RAT. It was disguised as an OpenClaw installer with the primary objective of stealing macOS credentials. Web3 Antivirus has further briefed the community about how the act was being carried out.

The package launches a fake CLI installer after it is installed normally. Once launched, it seeks macOS Keychain password. It is recommended not to do so because once shared, the malware can extract several pieces of information. This includes seed phrases, browser credentials, crypto wallet data, and SSH & cloud keys.

All the pieces find their way to the attacker’s server. Web3, with this, is seeing different types of threats for users worldwide.

Previously Flagged Threat

Web3 Antivirus previously flagged a threat from a legitimate Chrome extension. It warned that it was turning malicious after the ownership was transferred. This allows attackers to inject codes into web pages and steal the data of a user. The update, according to Web3 security stack, removed security headers and fingerprints before pulling malicious scripts from a remote server.

For the crypto community, such an act can turn into a theft for exchange sessions, compromised wallets, browser credentials, and seed phrase phishing.

It has named two extensions: QuickLens and ShotBird, adding that they have 7,000 and 800 users, respectively.

Top Web3 Security Threats in 2026

Some of the top Web3 security threats in 2026 are smart contract exploits and phishing & social engineering. The former largely pertains to vulnerabilities in code. This refers to infusing logic errors, input validation issues, and access control failures.

The latter, as the name suggests, involves making fake calls or impersonating partners to attack users and developers – even founders on some occasions.

Others on the list are wallet drainers, private key manipulation, and price oracle manipulation. The end goal of malicious actors is to steal data and drain funds or negatively impact the system.

Some of the common vulnerabilities are access control failures, logic errors, and unsigned API queries.

Highlighted Crypto News Today:

Nasdaq Collaboration Targets Pan-European Tokenized Securities Trading and Settlement

TagsWeb3

Related Questions

QWhat type of malicious software was the NPM package caught deploying, and what was its primary objective?

AThe malicious NPM package was caught deploying a RAT (Remote Access Trojan). Its primary objective was to steal macOS credentials.

QWhat specific user information can the malware extract after obtaining the macOS Keychain password?

AThe malware can extract seed phrases, browser credentials, crypto wallet data, and SSH & cloud keys.

QWhat previously flagged threat did Web3 Antivirus warn about involving a legitimate Chrome extension?

AWeb3 Antivirus warned about a legitimate Chrome extension that turned malicious after ownership was transferred, allowing attackers to inject code into web pages and steal user data.

QWhat are two of the top Web3 security threats highlighted for 2026?

ATwo of the top Web3 security threats for 2026 are smart contract exploits and phishing & social engineering.

QWhat are the names of the two malicious Chrome extensions mentioned, and how many users do they have respectively?

AThe two malicious Chrome extensions are named QuickLens and ShotBird, with 7,000 and 800 users respectively.

Related Reads

The Turning Point of the AI Bull Market: Leverage Blow-ups, Overcapacity in Compute, Why This Macro Analyst is Fully Bearish

AI Bull Market Reaches Inflection Point: Analyst Turns Bearish Due to Leverage, Chinese Competition, and Overcapacity Fidenza Macro analyst Geo Chen explains his decision to sell all AI semiconductor and infrastructure holdings in June, offering a comprehensive bearish thesis. He argues the AI-driven bull market has peaked, citing several key factors. First, unsustainable buying pressure: a massive influx of "low-quality" capital from Korean retail investors using highly leveraged ETFs on stocks like SK Hynix created a parabolic, fragile rally. Recent liquidations have wiped out billions and impacted over a million accounts, removing a key market driver. Second, a competitive threat: the rapid rise of powerful, cost-effective open-source AI models from China, such as MoonShot AI's Kimi K3 and Alibaba's Qwen 3.8, is commoditizing intelligence. This undermines the pricing power and high-valuation financing prospects of closed-source leaders like OpenAI and Anthropic, potentially creating a "single point of failure" for the ecosystem. Third, an impending capacity glut: while AI compute and components are currently in shortage, Chen warns this is typical of a cycle top. Massive, committed capex from cloud providers will likely lead to a supply overhang within 1-2 years. Data shows token spending has already peaked and declined since June, while bond spreads for data center companies are widening, signaling rising credit risk. Chen also highlights broader macro headwinds: the protracted Iran conflict acts as a persistent stagflationary force, and the Federal Reserve under Chair Kevin Warsh is losing credibility in its inflation fight. Long-term Treasury yields breaking above 5.2% present a new challenge for equities. In summary, Chen believes the convergence of speculative excesses, competitive disruption, looming overcapacity, and adverse macroeconomic conditions marks a significant turning point for the AI investment theme.

marsbit13m ago

The Turning Point of the AI Bull Market: Leverage Blow-ups, Overcapacity in Compute, Why This Macro Analyst is Fully Bearish

marsbit13m ago

Saeed Al-Marri: How Tokenization Unlocks New Opportunities for Shipping Funds

Said Al-Marri: How Tokenization Opens New Opportunities for Shipping Funds For centuries, commercial shipping has been a capital-intensive asset class limited to institutional funds and shipping dynasties. Said bin Saleh Al-Marri, CEO of Ethra Invest and Ethra Ship, aims to break down these barriers by combining Real World Asset (RWA) tokenization with conservative private equity principles. This bridges decentralized finance (DeFi) with the physical realities of global trade. Tokenization allows fractional ownership of ships on a blockchain, giving smaller investors access to previously inaccessible markets. However, Al-Marri warns it is not a regulatory loophole or a cure for asset illiquidity. The core physical risks are isolated in Special Purpose Vehicles (SPVs) for qualified investors. While tokenization enhances transparency and ownership record-keeping, Al-Marri stresses that a liquid secondary market depends on transparent asset valuation and must not interfere with ship operations managed by professionals. Regarding legal enforcement, smart contracts cannot physically seize a ship. Legal recourse still relies on traditional maritime courts, ship mortgages, and flag state laws, with blockchain records needing to mirror legal ownership in the SPV perfectly. Beyond ownership, the industry faces administrative hurdles like paper-based bills of lading. Al-Marri argues the bottleneck is legal and operational standardization, not technology. He advocates for a hybrid model combining digital trade documents and programmable settlements with support from regulated financial institutions, rather than a full crypto replacement for tools like Letters of Credit. A major challenge is decarbonizing the global fleet by 2050. Transitioning to green fuels requires massive upfront investment. Al-Marri emphasizes a conservative, holistic approach to underwriting these projects, evaluating technology, fuel availability, safety, and resale value. Investments must be justified under conservative forecasts, not just optimistic ones. By combining pragmatic risk management with digital infrastructure, leaders like Al-Marri show that the evolution of maritime finance is about mobilizing capital to build a modernized and sustainable global fleet, not just putting ships on a blockchain.

cryptonews.ru28m ago

Saeed Al-Marri: How Tokenization Unlocks New Opportunities for Shipping Funds

cryptonews.ru28m ago

Trading

Spot
活动图片