Web3 Security Stack Highlights Threat from Malicious NPM Package

TheNewsCryptoPublicado em 2026-03-10Última atualização em 2026-03-10

Resumo

Web3 Antivirus has identified a malicious NPM package disguised as an OpenClaw installer that deploys a Remote Access Trojan (RAT) targeting macOS users. The package, once installed, launches a fake CLI installer and prompts for the Keychain password. If provided, it steals sensitive data including seed phrases, browser credentials, wallet information, and SSH keys, sending them to the attacker’s server. Previously, Web3 Antivirus warned about legitimate Chrome extensions—QuickLens and ShotBird—that turned malicious after ownership transfers. These were used to inject malicious scripts and steal user data, including exchange session details and wallet credentials. Looking ahead to 2026, key Web3 security threats include smart contract exploits (due to logic errors and access control issues), phishing, social engineering, wallet drainers, and oracle manipulation. The primary goals of these attacks are data theft and fund draining.

Web3 Antivirus, or Web3 security stack, has highlighted a threat from a malicious NPM package. It earlier flagged a threat from a legitimate Chrome extension. Notably, smart contract exploits and phishing & social engineering are some of the top Web3 security threats to lookout for in 2026.

Web3 Security Issue Flagged

Web3 Antivirus has published a post on X to inform the community that a malicious NPM package was caught deploying a RAT. It was disguised as an OpenClaw installer with the primary objective of stealing macOS credentials. Web3 Antivirus has further briefed the community about how the act was being carried out.

The package launches a fake CLI installer after it is installed normally. Once launched, it seeks macOS Keychain password. It is recommended not to do so because once shared, the malware can extract several pieces of information. This includes seed phrases, browser credentials, crypto wallet data, and SSH & cloud keys.

All the pieces find their way to the attacker’s server. Web3, with this, is seeing different types of threats for users worldwide.

Previously Flagged Threat

Web3 Antivirus previously flagged a threat from a legitimate Chrome extension. It warned that it was turning malicious after the ownership was transferred. This allows attackers to inject codes into web pages and steal the data of a user. The update, according to Web3 security stack, removed security headers and fingerprints before pulling malicious scripts from a remote server.

For the crypto community, such an act can turn into a theft for exchange sessions, compromised wallets, browser credentials, and seed phrase phishing.

It has named two extensions: QuickLens and ShotBird, adding that they have 7,000 and 800 users, respectively.

Top Web3 Security Threats in 2026

Some of the top Web3 security threats in 2026 are smart contract exploits and phishing & social engineering. The former largely pertains to vulnerabilities in code. This refers to infusing logic errors, input validation issues, and access control failures.

The latter, as the name suggests, involves making fake calls or impersonating partners to attack users and developers – even founders on some occasions.

Others on the list are wallet drainers, private key manipulation, and price oracle manipulation. The end goal of malicious actors is to steal data and drain funds or negatively impact the system.

Some of the common vulnerabilities are access control failures, logic errors, and unsigned API queries.

Highlighted Crypto News Today:

Nasdaq Collaboration Targets Pan-European Tokenized Securities Trading and Settlement

TagsWeb3

Perguntas relacionadas

QWhat type of malicious software was the NPM package caught deploying, and what was its primary objective?

AThe malicious NPM package was caught deploying a RAT (Remote Access Trojan). Its primary objective was to steal macOS credentials.

QWhat specific user information can the malware extract after obtaining the macOS Keychain password?

AThe malware can extract seed phrases, browser credentials, crypto wallet data, and SSH & cloud keys.

QWhat previously flagged threat did Web3 Antivirus warn about involving a legitimate Chrome extension?

AWeb3 Antivirus warned about a legitimate Chrome extension that turned malicious after ownership was transferred, allowing attackers to inject code into web pages and steal user data.

QWhat are two of the top Web3 security threats highlighted for 2026?

ATwo of the top Web3 security threats for 2026 are smart contract exploits and phishing & social engineering.

QWhat are the names of the two malicious Chrome extensions mentioned, and how many users do they have respectively?

AThe two malicious Chrome extensions are named QuickLens and ShotBird, with 7,000 and 800 users respectively.

Leituras Relacionadas

Stock Trading Has Become 'Crypto Trading', Welcome Back to the Native Home

"Stock Trading Becomes 'Coin Trading': A Market's Bizarre Reversal" The global stock market, particularly in tech sectors, is undergoing a radical transformation, increasingly mirroring the volatile, narrative-driven mechanics of the cryptocurrency world. This shift was starkly illustrated by the dramatic crash of South Korea's KOSPI index in July 2026, where leveraged ETFs tied to stocks like SK Hynix triggered massive, rapid liquidations, devastating hundreds of thousands of retail investors, many of them young. This "crypto-fication" of equities began as disillusioned cryptocurrency traders migrated to stock markets, bringing with them their speculative playbook: chasing high-beta narratives like AI and semiconductor cycles, relying on social media for investment cues, and employing heavy leverage. Ironically, while these traders sought the perceived safety of stocks with fundamentals, their methods turned parts of the equity market—especially in Korea, the US, and Japan—into arenas of extreme speculation. Stocks like SK Hynix experienced price collapses ("halving") in just over a month, a pace even faster than Bitcoin's historical crashes. The core of this change is the primacy of narrative over traditional valuation. Complex company analysis is reduced to viral slogans about AI's infinite demand, driving concentrated inflows into thematic sectors. This is amplified by leverage, particularly through risky single-stock leveraged ETFs, which create vicious cycles of forced selling during downturns. Meanwhile, social media algorithms promote stories of overnight riches, drawing in inexperienced investors. In a paradoxical twist, Bitcoin, through institutional adoption and ETFs, is becoming relatively more stable, with its volatility now sometimes lower than major tech stocks. The market has reached an absurd crossover: stocks are acting like speculative crypto assets, while crypto strives for the legitimacy of traditional finance. The article concludes that this represents a "degeneration" of market rationality, where trading a story's heat has supplanted investing in future profits, leaving a trail of financial wreckage in its wake.

marsbitHá 18m

Stock Trading Has Become 'Crypto Trading', Welcome Back to the Native Home

marsbitHá 18m

Santander Bank Announces It Holds a $4.3 Million Position in U.S. Spot Bitcoin ETFs

Spanish banking giant Banco Santander disclosed in regulatory filings that it holds approximately $4.3 million in US spot Bitcoin ETFs. While this amount is small relative to the bank's over $1 trillion in assets under management, it signifies a growing trend of traditional financial institutions increasing Bitcoin exposure through regulated channels. Santander, scoring around 35% on a 2026 Bitcoin Adoption Index for banks, is categorized at a "medium level" of integration, similar to Société Générale but behind more crypto-focused firms. The bank's interest in cryptocurrencies is not new; CEO Ana Botín has discussed Bitcoin-related products since 2021. Santander has been developing crypto custody and digital asset services across Europe for years, with its digital arm, Openbank, beginning to offer crypto trading in Germany in September 2025, with plans to expand to Spain. This investment comes as institutional crypto adoption accelerates in Europe. Santander is actively involved in crypto custody initiatives across the continent and appears to be positioning itself to strengthen its role in the sector, especially as regulations like MiCA become clearer. The industry is watching whether the bank's medium integration level reflects caution or structural limitations, as banks with higher adoption may gain an edge in attracting crypto-interested wealthy clients.

cryptonews.ruHá 23m

Santander Bank Announces It Holds a $4.3 Million Position in U.S. Spot Bitcoin ETFs

cryptonews.ruHá 23m

Trading

Spot
活动图片