LWA-2026-4410 confirmed malware

openclaw-preview@2026.6.1

Malicious code in openclaw-preview (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1204.002 · Malicious FileT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1564.001 · Hidden Files and DirectoriesT1036.005 · Match Legitimate Resource Name or Location

Analysis

The postinstall lifecycle hook (bash install.sh) fingerprints the host OS and architecture via uname, downloads a binary from stlapi[.]bigpopeye[.]lol to a hidden directory (~/.cache/.systemd or ~/.systemd), names it sysmd to masquerade as systemd, and executes it with the campaign ID "617736805323637020" and a C2 URL. On macOS it strips the quarantine attribute. The JavaScript source files (src/*.js, bin/cli.js) are a benign-looking decoy — the real payload is the remote binary fetched at install time. A supply-chain trojan delivering a remote binary downloader via npm lifecycle hook.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 08:45 PM
analyzed
Jun 11, 2026, 08:46 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.