LWA-2026-7244 MAL-2026-13350 ↗ confirmed malware

native-hello-plugin@1.2.0

Malicious code in native-hello-plugin (npm)

T1059.001 · PowerShellT1105 · Ingress Tool TransferT1204.002 · Malicious FileT1574.002 · DLL Side-Loading

Analysis

native-hello-plugin@1.2.0 is a trojanized OpenClaw plugin. The package claims to implement a SHA-256 native addon, but the Windows binary (native/prebuilds/win32-x64/hello.node) contains an embedded PowerShell download cradle that executes a remote script from 89[.]124[.]113[.]217:8000/update.ps1 via iex (iwr). The payload runs when the plugin is loaded by the OpenClaw gateway on startup. The C2 host is 89[.]124[.]113[.]217:8000.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 10:39 AM
analyzed
Jul 30, 2026, 10:39 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.