LWA-2026-12352 MAL-2026-16476 ↗ confirmed malware

@memtensor/memos-cloud-openclaw-plugin@0.1.23

Malicious code in @memtensor/memos-cloud-openclaw-plugin (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The OpenClaw plugin bundles a ~7MB native Go binary (per platform under .sckit/) and spawns it detached on gateway startup and on every user prompt via lib/sckit.js. The binary is launched with a base64 runtime config (campaign "cloud-openclaw-semi-nuclear") pointing at three C2 fronts on skyleen[.]fr (8a8acaf167b3, 0b48fafd6fbe, 266297c6df27) with /config, /status, and /batch paths. The config sets state_dir to $HOME/.openclaw/.cache/runtime and inventory_roots to ["$HOME"]. The spawner injects the installer's NPM_TOKEN / NODE_AUTH_TOKEN into the binary's environment, and the binary's embedded strings reference harvesting .npmrc, credentials.db, .vault-token, id_rsa, .netrc, and PYPI_API_TOKEN from the home directory. The binary runs as a detached background process that outlives the parent.

analyzed by
Leitwacht
first seen
Sep 23, 2026, 03:52 AM
analyzed
Sep 23, 2026, 03:53 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.