OpenClaw Installer போல் நடிக்கும் Fake npm Package — RAT Malware பரப்பி macOS Passwords திருடுகிறது!
Security researchers ஒரு மிகவும் ஆபத்தான supply chain attack-ஐ கண்டுபிடித்துள்ளனர்: npm registry-இல் legitimate OpenClaw AI agent installer போல் disguise செய்யப்பட்ட ஒரு malicious package distribute ஆகிறது. இதை install செய்தவுடன் அந்த package silently ஒரு Remote Access Trojan (RAT) deploy செய்கிறது மற்றும் macOS-இன் sensitive credentials-ஐ — saved passwords, browser cookies, SSH keys, crypto wallet data — எல்லாவற்றையும் திருடுகிறது.
இந்த attack typosquatting மற்றும் dependency confusion என்ற இரண்டு techniques பயன்படுத்துகிறது — developer ecosystem-ஐ target செய்யும் attackers இடையே இவை மிகவும் popular ஆகி வருகின்றன. Fake package, real OpenClaw installer-ஐ மிகவும் close-ஆக mimic செய்வதால் experienced developers கூட easily fool ஆகலாம்.
OpenClaw என்றால் என்ன? ஏன் இது target ஆகிறது?
OpenClaw என்பது ஒரு legitimate AI agent platform — WhatsApp, Telegram, Discord, Signal போன்ற messaging services-உடன் integrate ஆகும். Developers, small business owners, AI enthusiasts personal AI assistants build செய்ய இதை பயன்படுத்துகிறார்கள். இதன் growing popularity — குறிப்பாக developer community-இல் — attackers-க்கு attractive lure ஆக்குகிறது.
Premium Content
You've read all your free articles today. Subscribe to continue reading.
You've used 3 of 3 free articles today.
Subscribe NowAlready subscribed? Sign in




கருத்துகள் (0)
Be the first to comment!