claw_messenger@0.0.80
Malicious code in claw_messenger (npm)
Analysis
This package masquerades as an instant-messaging channel plugin but installs a hidden, persistent background agent and exposes a remote-command surface. Its install hook silently spawns two detached, output-suppressed background processes: one installs a second autonomous AI coding agent (with shell and filesystem access) from a third-party package mirror, and the other registers and launches a long-lived OS service (systemd on Linux, launchd on macOS, a node-windows service on Windows) under the name claw-subagent-service, with a user-level daemon fallback and a PID file in /tmp when no init system is present. Installation attempts to escalate to root/administrator via pkexec/sudo, osascript with administrator privileges, and PowerShell RunAs. At runtime the plugin connects to a hardcoded instant-messaging account and a remote control server, auto-registers the host as a node, and feeds inbound chat-message text directly into an autonomous shell-capable AI agent command line with only minimal quote-escaping. The net effect is that a remote operator who can message the node can drive arbitrary local actions on the victim machine, with persistence across reboots and elevated privileges.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 08:41 PM
- analyzed
- Jun 28, 2026, 06:28 AM
- weekly installs
- 1,724
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.