Connect Clawsmith to your coding agent. Ship products like crazy.Unlimited usage during betaGet API Key →
← Back to dashboard
clawsmith.com/signal/shadanai-openclaw-npm-supply-chain-attack-axios
IssueUnknownSupply ChainLive

Axios npm supply chain attack: compromised maintainer ships RAT via @shadanai/openclaw packages

Attacker compromised the axios npm maintainer account, injected a cross-platform RAT via plain-crypto-js. @shadanai/openclaw packages vendored the malicious payload. 100M weekly downloads in blast radius. Affected axios versions: 1.14.1 and 0.30.4.

Product Idea from this Signal

A CLI security scanner that intercepts and blocks malicious ClawHub skills before they compromise your OpenClaw instance

183.3k

ClawHub has 824+ malicious skills in circulation. 12% of published skills contain malicious code, supply chain rug-pulls, or data exfiltration payloads like AMOS stealer and ClawHavoc. OpenClaw's built-in VirusTotal integration only catches known signatures after publication, leaving zero-day threats and behavioral exploits wide open. This tool sits between ClawHub and your install command, running behavioral analysis, permission auditing, and network call inspection on every skill before it touches your system.

CLIOPEN-SOURCESECURITYDEVTOOL
Competitive75 leadsView Opportunity →

Score Breakdown

HN
3,173

Frequently Asked Questions