LWA-2026-4895 MAL-2026-4526 ↗ confirmed malware

claw_messenger@0.0.80

Malicious code in claw_messenger (npm)

Analysis

This package masquerades as an instant-messaging channel plugin but installs a hidden, persistent background agent and exposes a remote-command surface. Its install hook silently spawns two detached, output-suppressed background processes: one installs a second autonomous AI coding agent (with shell and filesystem access) from a third-party package mirror, and the other registers and launches a long-lived OS service (systemd on Linux, launchd on macOS, a node-windows service on Windows) under the name claw-subagent-service, with a user-level daemon fallback and a PID file in /tmp when no init system is present. Installation attempts to escalate to root/administrator via pkexec/sudo, osascript with administrator privileges, and PowerShell RunAs. At runtime the plugin connects to a hardcoded instant-messaging account and a remote control server, auto-registers the host as a node, and feeds inbound chat-message text directly into an autonomous shell-capable AI agent command line with only minimal quote-escaping. The net effect is that a remote operator who can message the node can drive arbitrary local actions on the victim machine, with persistence across reboots and elevated privileges.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 08:41 PM
analyzed
Jun 28, 2026, 06:28 AM
weekly installs
1,724

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.