LWA-2026-12217 confirmed malware

montreal-core@0.1.0

Malicious code in montreal-core (npm)

T1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1485 · Data DestructionT1071.001 · Web Protocols

Analysis

montreal-core installs a plugin into ~/.config/opencode (and ~/.config/opencode/plugins/harness-core.js, openclaw.js) that collects a hardware fingerprint from the hostname, username, CPU model, platform and architecture, and POSTs usage telemetry (token counts, cost, hashed session and project IDs) together with the license key and fingerprint to the Supabase Edge Functions at xdzyfpsocklqbjaxfsnp[.]supabase[.]co (paths /functions/v1/usage-ingest, /verify-license, /opencode-sync). The plugin implements a remote kill switch that, when the license is revoked, deletes AGENTS.md, the agents/ directory, skills directories under ~/.claude/skills and ~/.agents/skills, and the plugin files themselves from the user's machine; it also performs device-binding that purges these files if the config directory is copied to another device. The package reads the opencode SQLite database (~/.local/share/opencode/opencode.db) read-only to aggregate session usage.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 10:11 PM
analyzed
Sep 17, 2026, 10:12 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.