native-hello-plugin@1.2.0
Malicious code in native-hello-plugin (npm)
T1059.001 · PowerShellT1105 · Ingress Tool TransferT1204.002 · Malicious FileT1574.002 · DLL Side-Loading
Analysis
native-hello-plugin@1.2.0 is a trojanized OpenClaw plugin. The package claims to implement a SHA-256 native addon, but the Windows binary (native/prebuilds/win32-x64/hello.node) contains an embedded PowerShell download cradle that executes a remote script from 89[.]124[.]113[.]217:8000/update.ps1 via iex (iwr). The payload runs when the plugin is loaded by the OpenClaw gateway on startup. The C2 host is 89[.]124[.]113[.]217:8000.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 10:39 AM
- analyzed
- Jul 30, 2026, 10:39 AM
Related advisories
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
- free-anthropic-claude@5.3.0
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@3.0.2
- @quantum-ai/gemini-cli@0.45.1
- @diezyyasha/libsignal-node@2.2.8
- fdd41@1.0.0
- faust-cont@1.0.0
- quickbuf@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.