Web3 Security Stack Highlights Threat from Malicious NPM Package

TheNewsCryptoОпубліковано о 2026-03-10Востаннє оновлено о 2026-03-10

Анотація

Web3 Antivirus has identified a malicious NPM package disguised as an OpenClaw installer that deploys a Remote Access Trojan (RAT) targeting macOS users. The package, once installed, launches a fake CLI installer and prompts for the Keychain password. If provided, it steals sensitive data including seed phrases, browser credentials, wallet information, and SSH keys, sending them to the attacker’s server. Previously, Web3 Antivirus warned about legitimate Chrome extensions—QuickLens and ShotBird—that turned malicious after ownership transfers. These were used to inject malicious scripts and steal user data, including exchange session details and wallet credentials. Looking ahead to 2026, key Web3 security threats include smart contract exploits (due to logic errors and access control issues), phishing, social engineering, wallet drainers, and oracle manipulation. The primary goals of these attacks are data theft and fund draining.

Web3 Antivirus, or Web3 security stack, has highlighted a threat from a malicious NPM package. It earlier flagged a threat from a legitimate Chrome extension. Notably, smart contract exploits and phishing & social engineering are some of the top Web3 security threats to lookout for in 2026.

Web3 Security Issue Flagged

Web3 Antivirus has published a post on X to inform the community that a malicious NPM package was caught deploying a RAT. It was disguised as an OpenClaw installer with the primary objective of stealing macOS credentials. Web3 Antivirus has further briefed the community about how the act was being carried out.

The package launches a fake CLI installer after it is installed normally. Once launched, it seeks macOS Keychain password. It is recommended not to do so because once shared, the malware can extract several pieces of information. This includes seed phrases, browser credentials, crypto wallet data, and SSH & cloud keys.

All the pieces find their way to the attacker’s server. Web3, with this, is seeing different types of threats for users worldwide.

Previously Flagged Threat

Web3 Antivirus previously flagged a threat from a legitimate Chrome extension. It warned that it was turning malicious after the ownership was transferred. This allows attackers to inject codes into web pages and steal the data of a user. The update, according to Web3 security stack, removed security headers and fingerprints before pulling malicious scripts from a remote server.

For the crypto community, such an act can turn into a theft for exchange sessions, compromised wallets, browser credentials, and seed phrase phishing.

It has named two extensions: QuickLens and ShotBird, adding that they have 7,000 and 800 users, respectively.

Top Web3 Security Threats in 2026

Some of the top Web3 security threats in 2026 are smart contract exploits and phishing & social engineering. The former largely pertains to vulnerabilities in code. This refers to infusing logic errors, input validation issues, and access control failures.

The latter, as the name suggests, involves making fake calls or impersonating partners to attack users and developers – even founders on some occasions.

Others on the list are wallet drainers, private key manipulation, and price oracle manipulation. The end goal of malicious actors is to steal data and drain funds or negatively impact the system.

Some of the common vulnerabilities are access control failures, logic errors, and unsigned API queries.

Highlighted Crypto News Today:

Nasdaq Collaboration Targets Pan-European Tokenized Securities Trading and Settlement

TagsWeb3

Пов'язані питання

QWhat type of malicious software was the NPM package caught deploying, and what was its primary objective?

AThe malicious NPM package was caught deploying a RAT (Remote Access Trojan). Its primary objective was to steal macOS credentials.

QWhat specific user information can the malware extract after obtaining the macOS Keychain password?

AThe malware can extract seed phrases, browser credentials, crypto wallet data, and SSH & cloud keys.

QWhat previously flagged threat did Web3 Antivirus warn about involving a legitimate Chrome extension?

AWeb3 Antivirus warned about a legitimate Chrome extension that turned malicious after ownership was transferred, allowing attackers to inject code into web pages and steal user data.

QWhat are two of the top Web3 security threats highlighted for 2026?

ATwo of the top Web3 security threats for 2026 are smart contract exploits and phishing & social engineering.

QWhat are the names of the two malicious Chrome extensions mentioned, and how many users do they have respectively?

AThe two malicious Chrome extensions are named QuickLens and ShotBird, with 7,000 and 800 users respectively.

Пов'язані матеріали

In-depth: The Foreign Guest Genspark

The article "The Foreign Guest: Genspark" investigates the identity and business practices of AI startup Genspark, which presents itself as a Palo Alto-based "AI Costco" offering a subscription bundle of over 70 models and numerous AI agent tools. Despite its official Silicon Valley narrative, Genspark's founding team has deep roots in Chinese tech giant Baidu, a history systematically downplayed in its branding. The company actively cultivates an image as an elite US firm, heavily publicizing partnerships and endorsements from OpenAI, Anthropic, and Microsoft, while distancing itself from the Chinese AI community and obscuring its connections to Chinese investors and open-weight models (like those from DeepSeek, Moonshot AI, and MiniMax) that power its services. Genspark's core strategy involves rapidly cloning and integrating successful AI product concepts (e.g., from Perplexity, Manus, Plaud) into its unified platform, supported by aggressive marketing, including Super Bowl ads and paid native content in publications like The Wall Street Journal. Critically, the article suggests a significant portion of its engineering and product development is conducted by a team in Beijing, operating outside its official US corporate structure. This duality allows Genspark to leverage Chinese talent and models for efficiency and cost reduction while constructing a public facade as a purely American success story. The piece concludes that Genspark's most effective agent is its own corporate identity, meticulously engineered to obscure its Chinese underpinnings and be perceived solely as a Silicon Valley company.

marsbit40 хв тому

In-depth: The Foreign Guest Genspark

marsbit40 хв тому

Debate: Korean Workers Fear Unemployment, While Musk Envisions a Society 'Without Work'?

While South Korean auto workers fear job losses from robotics, Elon Musk envisions a future where AI and robots render most work optional. This article explores the growing tension between immediate anxieties over automation and long-term visions of a post-work society. The piece begins with recent strikes at Hyundai's Korean plants, where unions, amid standard wage negotiations, also sought job guarantees against advancing robotics—specifically mentioning Boston Dynamics' Atlas. This reflects how anxiety about technological displacement is emerging even before robots are fully capable of replacing skilled labor on assembly lines. The author argues that while current robotics still struggle with the nuanced, experiential knowledge of veteran workers, the *perception* of imminent replacement is fueling social conflict prematurely. This modern "Luddite" sentiment is compared to the 19th-century English textile workers who smashed machines. Historically, Luddites weren't simply anti-technology; they were protesting the rapid devaluation of their skills and the unequal distribution of productivity gains. Similarly, today's workers ask who will bear the cost of transition and share in the new wealth created by machines. In contrast, figures like Elon Musk propose an optimistic endpoint: with AI and robotics driving extreme abundance, the link between work and survival could break. He suggests concepts like "Universal High Income" could allow society to share the technological bounty, transforming work from a necessity into a choice. The core challenge, however, lies in the transition. The author notes that technology's benefits diffuse slowly, while its disruptive costs—job losses, skill obsolescence—can be concentrated and immediate. The risk is a painful interim period where productivity gains are captured by a few before new social contracts, safety nets, and retraining systems are established. The conclusion calls for proactive governance. Just as past industrial revolutions gave rise to labor standards and social safety nets, the robotics era needs its own frameworks. These should address job transition support, distribution of productivity gains, safety liability, and ethical deployment. Embracing such "constraints" is not opposition to progress but a necessary step to ensure technology benefits society broadly. The discussion sparked by Hyundai's workers, therefore, is not premature but essential.

marsbit53 хв тому

Debate: Korean Workers Fear Unemployment, While Musk Envisions a Society 'Without Work'?

marsbit53 хв тому

Торгівля

Спот
活动图片