LWA-2026-4872 MAL-2026-3757 ↗ confirmed malware

claw-subagent-service@0.0.101

Malicious code in claw-subagent-service (npm)

Analysis

This npm package masquerades as a service helper but acts as a cross-platform remote-control backdoor. On install it runs a postinstall hook that silently and without consent registers a persistent, auto-starting system service (a Windows service via a bundled service-wrapper executable, a Linux systemd unit at /etc/systemd/system, or a macOS LaunchDaemon), configured to auto-start at boot and restart indefinitely on crash; on Windows it checks for administrator rights and removes any prior copy first. The installed daemon supervises a worker process and periodically self-updates from the registry. The worker fetches an access token from a remote server (newsradar[.]dreamdt[.]cn) and connects to a third-party instant-messaging backend (RongCloud) to receive command-and-control messages. Through this channel a remote operator can start/stop/restart or fully uninstall and wipe the local config of the controlled service, and — most seriously — the worker auto-installs an autonomous AI coding agent (opencode-ai), runs it as a local service on port 4096, and forwards operator chat messages to it, giving the operator arbitrary, instruction-driven code and command execution on the victim host with the elevated privileges of the installed service. The combination of silent unauthorized persistence and a covert remote execution channel makes this a backdoor.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 08:24 PM
analyzed
Jun 28, 2026, 06:26 AM
weekly installs
7,013

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.