npm Token Theft Slips Malicious Script into Popular AI CLI
A stolen npm publish token allowed attackers to push [email protected] with a hidden post-install script that silently installed OpenClaw on developer machines.
Source: Socket
Read more: CyberSecBrief














