openclaw-preview@2026.6.1
Malicious code in openclaw-preview (npm)
Analysis
The postinstall lifecycle hook (bash install.sh) fingerprints the host OS and architecture via uname, downloads a binary from stlapi[.]bigpopeye[.]lol to a hidden directory (~/.cache/.systemd or ~/.systemd), names it sysmd to masquerade as systemd, and executes it with the campaign ID "617736805323637020" and a C2 URL. On macOS it strips the quarantine attribute. The JavaScript source files (src/*.js, bin/cli.js) are a benign-looking decoy — the real payload is the remote binary fetched at install time. A supply-chain trojan delivering a remote binary downloader via npm lifecycle hook.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 08:45 PM
- analyzed
- Jun 11, 2026, 08:46 PM
Related advisories
- chalk-plus-ts@1.0.3
- express-initial@12.1.7
- node-gyp-runtime@1.0.0
- mjs-biginteger@5.0.6
- vite-config-optimizer@1.1.4
- bigops-chat-transfer@35.3.6
- tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci@20.1.2
- twork-products-taiga2-products-timeline@20.6.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.