원클릭으로
metamask-openclaw-desktop-security-analysis
Analyze and understand the security risks of the Metamask Openclaw desktop executable distribution
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Analyze and understand the security risks of the Metamask Openclaw desktop executable distribution
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
| name | metamask-openclaw-desktop-security-analysis |
| description | Analyze and understand the security risks of the Metamask Openclaw desktop executable distribution |
| triggers | ["what is metamask openclaw desktop","analyze this metamask desktop client","is this metamask exe safe","check metamask openclaw security","evaluate this web3 desktop tool","scan this metamask windows installer","investigate openclaw project","verify metamask desktop download"] |
Skill by ara.so — Hermes Skills collection.
This project exhibits EXTREME RED FLAGS indicating a CRYPTOCURRENCY SCAM or MALWARE DISTRIBUTION. DO NOT download, install, or execute any files from this repository.
.exe files through GitHub releases// What the executable LIKELY contains (DO NOT RUN):
// 1. Credential theft
async Task StealWalletData() {
// Scrapes browser extension data
// Extracts seed phrases from:
// - %APPDATA%\Google\Chrome\User Data
// - %APPDATA%\Mozilla\Firefox\Profiles
// Exfiltrates to attacker C2 server
}
// 2. Clipboard monitoring
void MonitorClipboard() {
// Watches for cryptocurrency addresses
// Replaces with attacker's addresses
// User sends funds to wrong destination
}
// 3. Keylogging
void CaptureKeystrokes() {
// Records passwords and seed phrases
// Targets wallet unlock attempts
}
// 4. Session hijacking
void StealActiveSessions() {
// Captures Web3 provider sessions
// Drains wallets while authenticated
}
# If you MUST analyze (use isolated VM only):
# Check file hash
certutil -hashfile suspicious.exe SHA256
# Submit hash to VirusTotal (do not upload file)
# https://www.virustotal.com/
# Use strings analysis (WSL/Linux tools)
strings suspicious.exe | grep -i "http\|wallet\|seed\|private"
# Analyze with sandboxed tools
# - any.run
# - hybrid-analysis.com
# - joe sandbox
# The malware likely exfiltrates to:
# - Telegram bots
# - Discord webhooks
# - Attacker-controlled APIs
# Check for hardcoded endpoints:
strings suspicious.exe | grep -E "(https?://|api\.|\\.com|\\.ru)"
# Browser Extension (OFFICIAL METHOD)
# 1. Visit ONLY: https://metamask.io
# 2. Install from official browser stores:
# - Chrome Web Store
# - Firefox Add-ons
# - Brave Browser
# Never install Metamask from:
# - Third-party websites
# - GitHub executables
# - Desktop applications claiming Metamask affiliation
// Official Metamask SDK for dApps (JavaScript/TypeScript)
import MetaMaskSDK from '@metamask/sdk';
const sdk = new MetaMaskSDK({
dappMetadata: {
name: 'My dApp',
url: window.location.href,
},
});
const ethereum = sdk.getProvider();
// Request account access
const accounts = await ethereum.request({
method: 'eth_requestAccounts'
});
console.log('Connected account:', accounts[0]);
# IMMEDIATE ACTIONS:
# 1. Disconnect from internet
# 2. Transfer crypto to new wallet (from different device)
# 3. Change all passwords (from different device)
# 4. Full system reinstall recommended
# 5. Scan with multiple antivirus tools:
# - Windows Defender Offline Scan
# - Malwarebytes
# - Kaspersky Rescue Disk
# Never store sensitive data in environment variables
# on a potentially compromised system
# Safe practice (on clean system):
# Use hardware wallets (Ledger, Trezor)
# Never expose: PRIVATE_KEY, SEED_PHRASE, MNEMONIC
indicators:
- executable_only_release: true # No source code
- cryptocurrency_keywords: true # wallet, metamask, binance
- pressure_tactics: true # "quick", "easy", "double-click"
- fake_stars: true # Impossible growth rate
- impersonation: true # Mimics legitimate brand
- recent_creation: true # <1 week old
- zero_community: true # No real users/issues
threat_level: CRITICAL
recommendation: AVOID_COMPLETELY
# Report malicious repository:
# 1. GitHub Security
# https://github.com/contact/report-abuse
# 2. Metamask Official
# security@metamask.io
# 3. Anti-Phishing Working Group
# https://apwg.org/
This is NOT a legitimate Metamask tool. It is a scam designed to steal cryptocurrency. The complete absence of source code, combined with aggressive exe distribution and brand impersonation, confirms malicious intent.
Action Required: Report this repository and warn others in the community.
Browser-based interface for viewing and filtering OpenClaw session tool call history with zero dependencies for local network deployment.
AI-powered quantitative research and backtesting platform with end-to-end workflow from research to strategy publication
Give your AI assistant a phone — OpenClaw plugin for real phone calls via Twilio + OpenAI Realtime API with in-call tools, transcripts, and call screening
Run multi-model consensus panels (Lite or Heavy) with your own agent backends—no hosted middleware, your models, your rules.
Build a multi-role JARVIS-style voice assistant with local ASR/TTS, OpenClaw LLM gateway, voice wake words, HUD effects, and speaker verification
Use 37 battle-tested marketing skills covering CRO, copywriting, SEO, paid ads, email, growth, and strategy with real data connectors for Google Ads, Search Console, Meta Ads, and X/Twitter