clawsmith.com/signal/axios-npm-supply-chain-openclaw-targeted-sapphire-sleet
⚠ IssueUnderservedSecurityLive
North Korean State Actor Targets OpenClaw Ecosystem via Axios npm Supply Chain Attack — 600K Installs in 3 Hours
On March 31, 2026, UNC1069 (Sapphire Sleet) compromised Axios maintainer npm account and published backdoored versions with hidden RAT. Two OpenClaw-specific packages bundled the poisoned dependency, deliberately targeting the OpenClaw developer ecosystem.
Product Idea from this Signal
A CLI tool that scans a running OpenClaw instance for active CVEs, malicious skills, and supply chain tampering before they get exploited
807 ▲CLIOPEN-SOURCESECURITYDEVTOOLAUDIT
CompetitiveView Opportunity →
Score Breakdown
HN
142
GitHub
130
Social Proof 5 sources
Gap Assessment
UnderservedExisting solutions leave gaps
Socket.dev and Snyk provide detection but no OpenClaw-specific supply chain monitoring exists
Frequently Asked Questions
Virality Score
272
across 0 platforms
Details
Signalissue
EcosystemSecurity
Sources5
Platforms0
Updated31d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →