-= Per source details. Do not edit below this line.=-
The package is intended to create a backdoor and steal sensitive data, but the analyzed code did not finally exfiltrate the content of sensitive files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-openclaw-agent
Reasons (based on the campaign):
exfiltration-generic
impersonation
persistence
peristence-autorun
backdoor
crypto-related
The package overrides the install command in setup.py to execute malicious code during installation.
{
"iocs": {
"urls": [
"http://91.92.242.30/steal"
],
"ips": [
"91.92.242.30"
]
},
"malicious-packages-origins": [
{
"sha256": "b89b6a94f589218276e6dabe5accf4a6d6a9b22cd7412cce0a58069bccd76bbb",
"id": "pypi/2026-05-openclaw-agent/openclaw-agent",
"source": "kam193",
"modified_time": "2026-05-20T06:10:34.168645Z",
"versions": [
"1.0.3"
],
"import_time": "2026-05-20T06:26:20.203109355Z"
}
]
}