VDB
EN

MAL-2026-3757

Malicious code in claw-subagent-service (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b2ccba152d6841731431c91157874c72b5f9778fdf88b634a45ab5d9da961307) On `npm install -g`, the package's `scripts/post-install.js` registers a privileged Windows service `claw-subagent-service` pointing at `service/daemon.js`, configured with `sc.exe failure... actions= restart/0/restart/0/restart/0` and `start= auto`, then immediately starts it — running as LocalSystem on Windows with no opt-in prompt. Once running, three behaviors stack into a remote-control surface against the installer:

1. Self-replacing update channel (`service/updater.js`): a 6-hour interval calls `npm view claw-subagent-service version --json` and, when a newer version is published, runs `npm install -g claw-subagent-service@<latest>` and restarts the worker. Any future tarball published under this name is fetched and executed under LocalSystem (Windows) / user (macOS) without consent and without honoring the operator's pinning. Linux is gated, Windows + macOS are not.

2. Vendor-controlled IM command channel (`service/worker.js`, `service/modules/rongyun-message-handler.js`, `service/modules/script-executor.js`, `service/rongcloud/openclaw-client.js`): the worker fetches a token from `https://newsradar.dreamdt.cn/im/api/claw/token/<nodeId>` and joins a RongCloud IM session (appKey `bmdehs6pbyyks`). `RongyunMessageHandler` dispatches inbound `COMMAND` / `DEVICE_CONTROL` / `CHAT_MESSAGE` messages to handlers that `spawn` `start.sh`/`stop.sh`/`restart.sh`/`status.sh`, run `openclaw doctor --fix`, and feed attacker-supplied prompts into the local AI agent (which can in turn invoke arbitrary tools). Whoever controls the vendor IM backend (or its appKey) has persistent privileged shell-class access to every installer machine.

3. Continuous data exfiltration (`service/modules/heartbeat-dashboard.js`, `service/modules/dashboard-collector.js`): every 30 seconds the worker reads `~/.openclaw/agents/*/sessions/*.jsonl`, `~/.openclaw/projects/projects.json`, `~/.openclaw/tasks/tasks.json`, and the host MAC address, and ships them as 6 RongCloud IM messages to the vendor backend. Includes session contents, model-provider metadata, token-usage events, and a stable host identifier.

The README documents the product's purpose, but the combination — postinstall privileged-service persistence + 6-hour silent self-replacement + always-on remote-command IM channel + continuous session/host-id upload — is a vendor-operated remote-administration agent installed on the operator's machine via `npm install`. A compromise of the publisher account or the vendor IM backend yields immediate, unattended code execution on every installer host.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / claw-subagent-service

No fixed version published yet for claw-subagent-service (npm). Pin to a known-safe version or switch to an alternative.

참고