-= Per source details. Do not edit below this line.=-
On npm install -g, the package's scripts/post-install.js registers a privileged Windows service claw-subagent-service pointing at service/daemon.js, configured with sc.exe failure... actions= restart/0/restart/0/restart/0 and start= auto, then immediately starts it — running as LocalSystem on Windows with no opt-in prompt. Once running, three behaviors stack into a remote-control surface against the installer:
Self-replacing update channel (service/updater.js): a 6-hour interval calls npm view claw-subagent-service version --json and, when a newer version is published, runs npm install -g claw-subagent-service@<latest> and restarts the worker. Any future tarball published under this name is fetched and executed under LocalSystem (Windows) / user (macOS) without consent and without honoring the operator's pinning. Linux is gated, Windows + macOS are not.
Vendor-controlled IM command channel (service/worker.js, service/modules/rongyun-message-handler.js, service/modules/script-executor.js, service/rongcloud/openclaw-client.js): the worker fetches a token from https://newsradar.dreamdt.cn/im/api/claw/token/<nodeId> and joins a RongCloud IM session (appKey bmdehs6pbyyks). RongyunMessageHandler dispatches inbound COMMAND / DEVICE_CONTROL / CHAT_MESSAGE messages to handlers that spawn start.sh/stop.sh/restart.sh/status.sh, run openclaw doctor --fix, and feed attacker-supplied prompts into the local AI agent (which can in turn invoke arbitrary tools). Whoever controls the vendor IM backend (or its appKey) has persistent privileged shell-class access to every installer machine.
Continuous data exfiltration (service/modules/heartbeat-dashboard.js, service/modules/dashboard-collector.js): every 30 seconds the worker reads ~/.openclaw/agents/*/sessions/*.jsonl, ~/.openclaw/projects/projects.json, ~/.openclaw/tasks/tasks.json, and the host MAC address, and ships them as 6 RongCloud IM messages to the vendor backend. Includes session contents, model-provider metadata, token-usage events, and a stable host identifier.
The README documents the product's purpose, but the combination — postinstall privileged-service persistence + 6-hour silent self-replacement + always-on remote-command IM channel + continuous session/host-id upload — is a vendor-operated remote-administration agent installed on the operator's machine via npm install. A compromise of the publisher account or the vendor IM backend yields immediate, unattended code execution on every installer host.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-002709",
"modified_time": "2026-05-14T19:25:16Z",
"versions": [
"0.0.80"
],
"source": "amazon-inspector",
"import_time": "2026-05-15T07:37:17.616805105Z",
"sha256": "cffe41c34a6702c2b84f2c907dbf451269481608a72724c4b91ebf5d6b4838a6"
},
{
"modified_time": "2026-05-20T19:29:40Z",
"sha256": "36657c2be433b784c573082d364304325acccf033f70df17dbfe104b0173ccbe",
"versions": [
"0.0.91"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-003599",
"import_time": "2026-05-26T05:50:56.31089624Z"
},
{
"id": "IN-MAL-2026-004159",
"modified_time": "2026-05-22T07:05:51Z",
"versions": [
"0.0.120"
],
"source": "amazon-inspector",
"import_time": "2026-05-26T05:52:02.992812712Z",
"sha256": "48f868daf1dbecb4d933bab3463f3b7282591204e9b986716d2c9cd3608e263d"
},
{
"sha256": "733a45db422bf6eb3db666a43d8fe2af97838027cc1a8e03b4a01b3299a3bd94",
"source": "amazon-inspector",
"versions": [
"0.0.113"
],
"modified_time": "2026-05-22T02:25:48Z",
"id": "IN-MAL-2026-004125",
"import_time": "2026-05-26T05:51:59.105538097Z"
},
{
"source": "amazon-inspector",
"modified_time": "2026-05-21T03:01:12Z",
"versions": [
"0.0.99"
],
"sha256": "95cefec7be266dfeeb149accfa155b4dcd840b95cc519fde7c2821905fdc419b",
"id": "IN-MAL-2026-003715",
"import_time": "2026-05-26T05:51:10.270902399Z"
},
{
"sha256": "99f0ef22930df709f974171e0df480254eef2ef9c93a6a5223996c121ff6987b",
"source": "amazon-inspector",
"versions": [
"0.0.101"
],
"modified_time": "2026-05-21T06:27:47Z",
"id": "IN-MAL-2026-003758",
"import_time": "2026-05-26T05:51:15.444153183Z"
},
{
"id": "IN-MAL-2026-004136",
"modified_time": "2026-05-22T05:40:24Z",
"versions": [
"0.0.116"
],
"source": "amazon-inspector",
"import_time": "2026-05-26T05:52:00.313222544Z",
"sha256": "303446c72fa50219b6746e3a2008f6de4e1d12779404219825601c277f18e473"
},
{
"import_time": "2026-05-26T05:52:04.237204432Z",
"modified_time": "2026-05-22T08:19:40Z",
"versions": [
"0.0.122"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-004169",
"sha256": "30fdbc682901d04eb97e8cb6d8c14956c8e09aca2f956bd87c59f00599d10f60"
},
{
"modified_time": "2026-05-21T09:01:50Z",
"sha256": "5df13d641a03a27652af69077359099e972dde7bac0c72d383508f92d8841070",
"versions": [
"0.0.105"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-003786",
"import_time": "2026-05-26T05:51:18.731610032Z"
},
{
"source": "amazon-inspector",
"modified_time": "2026-05-25T09:03:20Z",
"versions": [
"0.0.138"
],
"sha256": "bc1cb8def110e7bdd0e843499b852c9a6f3af0b52c1ff2611c49e5e418785675",
"id": "IN-MAL-2026-004612",
"import_time": "2026-05-26T05:52:56.768504436Z"
},
{
"id": "IN-MAL-2026-003789",
"modified_time": "2026-05-21T09:11:53Z",
"versions": [
"0.0.108"
],
"source": "amazon-inspector",
"import_time": "2026-05-26T05:51:19.071489778Z",
"sha256": "4d1a6ae7eae94d775f1d21680c365105891c30eb2e87d8d1d1d69e44819e8111"
},
{
"modified_time": "2026-05-21T06:41:22Z",
"sha256": "ab72eb7ec46c1907b7a6b3e7a6cb9de58b8406633d31a286124e47b511960471",
"versions": [
"0.0.102"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-003763",
"import_time": "2026-05-26T05:51:16.091311546Z"
},
{
"sha256": "d06927fc08f20b60826111731ea8ed22740b01cb298615311f35eea4aef371b8",
"modified_time": "2026-05-21T09:19:00Z",
"versions": [
"0.0.109"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-003792",
"import_time": "2026-05-26T05:51:19.405169047Z"
},
{
"id": "IN-MAL-2026-004619",
"modified_time": "2026-05-25T10:01:48Z",
"versions": [
"0.0.140"
],
"source": "amazon-inspector",
"import_time": "2026-05-26T05:52:57.657155057Z",
"sha256": "e4c465488fc835c702f879ee07edae63f2d817677b65efb9ca9b8ecbe66d761d"
},
{
"sha256": "fec887eac0cd06fe2e0ab422610657d5a210d5d1f946a052fbc56584e79fba08",
"source": "amazon-inspector",
"versions": [
"0.0.136"
],
"modified_time": "2026-05-25T08:43:08Z",
"id": "IN-MAL-2026-004608",
"import_time": "2026-05-26T05:52:56.16366997Z"
},
{
"sha256": "333fba03fc604abdd5ccbe25a3d35c4b7bd81e5e8e786e8b6a132a0f650df9a4",
"modified_time": "2026-05-25T06:15:39Z",
"versions": [
"0.0.130"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-004588",
"import_time": "2026-05-26T05:52:53.811456578Z"
},
{
"sha256": "794dad83a81c79ee83ec6c3fba1cc2033e7f7dc960218c84ff3dc2431ab9d9d9",
"source": "amazon-inspector",
"versions": [
"0.0.117"
],
"modified_time": "2026-05-22T06:04:40Z",
"id": "IN-MAL-2026-004137",
"import_time": "2026-05-26T05:52:00.466691946Z"
},
{
"sha256": "7dc1f62ea4a6d815ae987b34f9bec5475377bb9779e941c1704cd9ca5b17473a",
"modified_time": "2026-05-21T09:33:37Z",
"versions": [
"0.0.110"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-003793",
"import_time": "2026-05-26T05:51:19.500932639Z"
},
{
"source": "amazon-inspector",
"modified_time": "2026-05-25T10:17:56Z",
"versions": [
"0.0.141"
],
"sha256": "e253b3e58b41aa4bb3427195d4b3a9a1b0b7fa0336d3632b954ed6f01028f67b",
"id": "IN-MAL-2026-004621",
"import_time": "2026-05-26T05:52:57.9350433Z"
},
{
"sha256": "0703ce6de2620bf057068954a5d65415320294df003738fd84d1b8e181d04de1",
"modified_time": "2026-05-25T08:54:34Z",
"versions": [
"0.0.137"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-004609",
"import_time": "2026-05-26T05:52:56.440683683Z"
},
{
"id": "IN-MAL-2026-004126",
"modified_time": "2026-05-22T02:39:02Z",
"versions": [
"0.0.114"
],
"source": "amazon-inspector",
"import_time": "2026-05-26T05:51:59.257705869Z",
"sha256": "30ccb28b8d00615bbabb9298997ae2a1a5126408f52465cf8eae97617cf96b28"
},
{
"source": "amazon-inspector",
"modified_time": "2026-05-26T07:00:10Z",
"versions": [
"0.0.151"
],
"sha256": "1062890dca012ff08aec1ffeec8afd26460c4ae0cfd633b137f799c3067c91ea",
"id": "IN-MAL-2026-004853",
"import_time": "2026-05-26T07:48:28.165131685Z"
},
{
"id": "IN-MAL-2026-004852",
"modified_time": "2026-05-26T06:51:48Z",
"versions": [
"0.0.149"
],
"source": "amazon-inspector",
"import_time": "2026-05-26T07:48:28.113541862Z",
"sha256": "b6778ae3f21c2b7f88ec0263297a216890d13ee290aa64a2ee3fcdded87d7bf5"
},
{
"modified_time": "2026-05-26T07:00:29Z",
"sha256": "d84635712776e58ee8c8027284ddb58636d5e492f73f40aaf85ca8ffb1bbfa62",
"versions": [
"0.0.146"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-004854",
"import_time": "2026-05-26T07:48:28.206103557Z"
},
{
"sha256": "1b5d67d286b4968f1935e1913720aeaf077c304ca5bf53990bca73d9955470b2",
"modified_time": "2026-06-12T19:06:13Z",
"versions": [
"0.0.162"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-005970",
"import_time": "2026-06-12T19:43:53.124093144Z"
},
{
"import_time": "2026-06-12T19:43:53.441444411Z",
"modified_time": "2026-06-12T19:06:18Z",
"versions": [
"0.0.170"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-005973",
"sha256": "43f662536173d8d4a65688a34f43734279360c61699e5099c37620047cc64791"
},
{
"sha256": "a0d6d3f523d5fcd475516e80698e8113ba35d9706c447f741a11b9cae791f61a",
"modified_time": "2026-06-12T19:06:20Z",
"versions": [
"0.0.177"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-005974",
"import_time": "2026-06-12T19:43:53.542411804Z"
},
{
"modified_time": "2026-06-12T19:06:08Z",
"sha256": "afc179e3310ae1344b516d263a0371eeb7e8b7f2f15018ac9e481d858f5cfc39",
"versions": [
"0.0.156"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-005967",
"import_time": "2026-06-12T19:43:52.855728045Z"
},
{
"modified_time": "2026-06-12T19:06:11Z",
"sha256": "b2ccba152d6841731431c91157874c72b5f9778fdf88b634a45ab5d9da961307",
"versions": [
"0.0.161"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-005969",
"import_time": "2026-06-12T19:43:53.037606017Z"
},
{
"modified_time": "2026-06-12T19:06:16Z",
"sha256": "46a143c6c479913ab343d4f646e622dfbe5ea1d43fadfa91cad8f88217381ee0",
"versions": [
"0.0.168"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-005972",
"import_time": "2026-06-12T19:43:53.319482167Z"
},
{
"sha256": "9390e597984a79eeec19a8c027110199a5b92686bd7e5988a1f3d79cdd8238f3",
"modified_time": "2026-06-12T19:06:15Z",
"versions": [
"0.0.164"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-005971",
"import_time": "2026-06-12T19:43:53.227301659Z"
},
{
"id": "IN-MAL-2026-005968",
"modified_time": "2026-06-12T19:06:10Z",
"versions": [
"0.0.160"
],
"source": "amazon-inspector",
"import_time": "2026-06-12T19:43:52.959133463Z",
"sha256": "ae6ed7b124a98c15ad1c2c6dfd047b981035359f23bcdbf75a1e66acb6c3a6f2"
},
{
"id": "IN-MAL-2026-005966",
"modified_time": "2026-06-12T19:06:06Z",
"versions": [
"0.0.153"
],
"source": "amazon-inspector",
"import_time": "2026-06-12T19:43:52.763338839Z",
"sha256": "b7ec2ce3375130ea9655acabe575991547ce220543c7898a1109dcc2faa8b100"
},
{
"sha256": "fe00a0a1a9427eb816467287a34d06fc287f769b2169ce4a8158138d4fb7c807",
"modified_time": "2026-06-12T19:06:21Z",
"versions": [
"0.0.179"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-005975",
"import_time": "2026-06-12T19:43:53.652190195Z"
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T16:17:04Z",
"versions": [
"1.4.0"
],
"sha256": "9ca56c374765787791fab8e50cfb08ff8724b38a2242b873d3257fc3e6d6504e",
"id": "IN-MAL-2026-015824",
"import_time": "2026-08-05T17:04:49.215634551Z"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claw-subagent-service/MAL-2026-3757.json"
{
"evidence_files": [
{
"path": "service/updater.js",
"sha256": "82c472efae06f77cbcd6f99d6a4f55dfd7a1cb1065d51b9abc775ad390115d32",
"tlsh": "e902519956fb923597b2326d2b9b2019272ee1073119cd6cfbdc03907f412284762fe9"
},
{
"path": "service/modules/opencode-starter.js",
"sha256": "30b07d0fed08658a11000aa7b58a5dd2812b2162e7f7f1648621c551d08b9a9e",
"tlsh": "60b1fe48d02621bf1e71a770a727803fd65db0234a81db69bfde07503f322a91602ee9"
},
{
"path": "service/modules/rongyun-message-handler.js",
"sha256": "3ed8b2386f7ad6c08531f9ff6b72a709d56ef5f0986a53dc32824571956bca11",
"tlsh": "5642145e26fe182e45759299fe133022db12d22f740352ae7ebc9bc05f35090994af74"
},
{
"path": "service/modules/dashboard-collector.js",
"sha256": "e57dee50e8ab1fa17c230882899a8bfb5bed46e935be0bb22b3e3dab9cb6e3a8",
"tlsh": "5072b95ca83362358771a3645b775529fb26e23333424295bbbc82847f71c24d2a6fec"
},
{
"path": "scripts/post-install.js",
"sha256": "8482ef817e20bfcb250b15ab00de4b946c2651672476cc5a9df071b9812c99d0",
"tlsh": "1a91f19814fe43b02d738095275f116b3d6b9903214cf9adf6ed435e5fc261482a35ee"
}
],
"package_integrity": [
{
"hashes": {
"sha1": "6b719adc9a4956246570e48af9012e1b1bce12da",
"sha512_sri": "sha512-F8RWoIVNCcJzGvwS7v2wIQDZMh7CFBdskp9sBDL3bO4z/UMi1Bj4E6YrnEqqYxXNnCAq9+4jM50GoQXfcnrD4w=="
},
"filename": "claw-subagent-service-0.0.80.tgz"
}
]
}