A digital worm attacks npm packages in a supply chain attack, stealing cryptocurrency keys and API credentials.
Blockchain News

Critical npm Worm SANDWORM_MODE Steals Crypto Keys in Devastating Supply Chain Attack

Global, April 2025: A sophisticated, self-replicating worm is actively compromising developer environments worldwide by infiltrating the npm registry. Dubbed SANDWORM_MODE, this malicious software targets over 19 packages to harvest sensitive data, including cryptocurrency private keys, BIP39 mnemonics, digital wallet files, and API keys for large language models. This represents a live and ongoing npm supply […]

Security dashboard alert for hidden backdoors in OpenClaw plugins targeting ClawHub users.
Blockchain News

Hidden Backdoors in OpenClaw Plugins Expose Users to Coordinated Attacks

Global, March 2025: A critical security flaw has shaken the burgeoning open-source AI community. Multiple cybersecurity firms have independently exposed hidden backdoors within plugins for OpenClaw, a rapidly growing AI agent framework. These vulnerabilities, which exploited weak plugin verification checks on the official ClawHub marketplace, enabled coordinated attacks targeting users. The discovery has forced the […]