Compromised npm package silently installs OpenClaw on developer machines