Currencies38260
Market Cap$ 2.32T-1.10%
24h Spot Volume$ 26.20B-5.24%
DominanceBTC56.92%-0.07%ETH10.10%+1.89%
ETH Gas0.31 Gwei
Cryptorank
/

Web3 Security Stack Highlights Threat from Malicious NPM Package


Web3 Security Stack Highlights Threat from Malicious NPM Package

Share:

AI Overview

Web3 Antivirus flagged a malicious NPM package (disguised as an OpenClaw installer) deploying a RAT that targets macOS Keychain to exfiltrate seed phrases, browser credentials, crypto wallet data, SSH and cloud keys in 2026. It previously warned that Chrome extensions QuickLens (7,000 users) and ShotBird (800 users) turned malicious after ownership transfer, enabling remote script injection and credential theft that risks CEX sessions, wallets and DeFi users. Web3 security outlook for 2026 highlights top crypto threats: smart contract exploits, phishing & social engineering, wallet drainers, private‑key and price‑oracle manipulation—critical risks to adoption and DeFi/CEX integrity.

Bearish

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

  • Web3 security stack has flagged a threat from a malicious NPM package.
  • It earlier flagged a threat from a legitimate Chrome extension.
  • Smart contract exploits and phishing & social engineering are the top threats in 2026.

Web3 Antivirus, or Web3 security stack, has highlighted a threat from a malicious NPM package. It earlier flagged a threat from a legitimate Chrome extension. Notably, smart contract exploits and phishing & social engineering are some of the top Web3 security threats to lookout for in 2026.

Web3 Security Issue Flagged

Web3 Antivirus has published a post on X to inform the community that a malicious NPM package was caught deploying a RAT. It was disguised as an OpenClaw installer with the primary objective of stealing macOS credentials. Web3 Antivirus has further briefed the community about how the act was being carried out.

The package launches a fake CLI installer after it is installed normally. Once launched, it seeks macOS Keychain password. It is recommended not to do so because once shared, the malware can extract several pieces of information. This includes seed phrases, browser credentials, crypto wallet data, and SSH & cloud keys.

All the pieces find their way to the attacker’s server. Web3, with this, is seeing different types of threats for users worldwide.

Previously Flagged Threat

Web3 Antivirus previously flagged a threat from a legitimate Chrome extension. It warned that it was turning malicious after the ownership was transferred. This allows attackers to inject codes into web pages and steal the data of a user. The update, according to Web3 security stack, removed security headers and fingerprints before pulling malicious scripts from a remote server.

For the crypto community, such an act can turn into a theft for exchange sessions, compromised wallets, browser credentials, and seed phrase phishing.

It has named two extensions: QuickLens and ShotBird, adding that they have 7,000 and 800 users, respectively.

Top Web3 Security Threats in 2026

Some of the top Web3 security threats in 2026 are smart contract exploits and phishing & social engineering. The former largely pertains to vulnerabilities in code. This refers to infusing logic errors, input validation issues, and access control failures.

The latter, as the name suggests, involves making fake calls or impersonating partners to attack users and developers – even founders on some occasions.

Others on the list are wallet drainers, private key manipulation, and price oracle manipulation. The end goal of malicious actors is to steal data and drain funds or negatively impact the system.

Some of the common vulnerabilities are access control failures, logic errors, and unsigned API queries.

Highlighted Crypto News Today:

Nasdaq Collaboration Targets Pan-European Tokenized Securities Trading and Settlement

Read the article at TheNewsCrypto

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

Read More

China’s Moonshot Reportedly Stole U.S. AI Tech for Kimi K3

China’s Moonshot Reportedly Stole U.S. AI Tech for Kimi K3

In Brief Kratsios says Moonshot AI distilled Anthropic's Fable to build its Kimi K3 ...
Forget Nvidia: The next big AI trade could be crypto and blockchain

Forget Nvidia: The next big AI trade could be crypto and blockchain

Franklin Templeton’s Sandy Kaul and Circle CEO Jeremy Allaire argue that as autonomou...