Compromised npm Package Stealthily Installs AI Agent OpenClaw on Developer Machines
A widely used npm package was compromised, silently installing the powerful AI agent OpenClaw on developer systems. This incident highlights critical supply chain vulnerabilities and the dangers of AI agents with broad system access.