Compromised npm package silently installs OpenClaw on developer machines – CSO Online
A new security bypass has users installing AI agent OpenClaw — whether they intended to or not. Researchers have discovered that a compromised npm publish token pushed an update for…