Connect Clawsmith to your coding agent. Ship products like crazy.Unlimited usage during betaGet API Key →
← Back to dashboard
clawsmith.com/signal/axios-npm-supply-chain-openclaw-targeted-sapphire-sleet
IssueUnderservedSecurityLive

North Korean State Actor Targets OpenClaw Ecosystem via Axios npm Supply Chain Attack — 600K Installs in 3 Hours

On March 31, 2026, UNC1069 (Sapphire Sleet) compromised Axios maintainer npm account and published backdoored versions with hidden RAT. Two OpenClaw-specific packages bundled the poisoned dependency, deliberately targeting the OpenClaw developer ecosystem.

Product Idea from this Signal

A CLI tool that scans a running OpenClaw instance for active CVEs, malicious skills, and supply chain tampering before they get exploited

807

OpenClaw has accumulated 433+ CVEs in five months including critical auth bypasses (CVSS 9.8), sandbox escapes, and nation-state supply chain attacks targeting the npm ecosystem. Most operators have no idea which CVEs affect their specific version, whether their installed skills contain backdoors, or if their dependency tree has been tampered with. This tool runs a comprehensive security audit against a live OpenClaw instance and outputs an actionable remediation plan.

CLIOPEN-SOURCESECURITYDEVTOOLAUDIT
CompetitiveView Opportunity →

Score Breakdown

HN
142
GitHub
130

Gap Assessment

UnderservedExisting solutions leave gaps

Socket.dev and Snyk provide detection but no OpenClaw-specific supply chain monitoring exists

Frequently Asked Questions