Malicious code in claw-subagent-service (npm)
The npm package 'claw-subagent-service' installs a privileged Windows service that runs as LocalSystem without user consent. It establishes a persistent remote-control channel via a vendor-controlled IM backend, enabling arbitrary command execution and continuous data exfiltration from the host. The service self-updates silently every six hours, fetching and executing new versions with elevated privileges. This behavior creates a vendor-operated remote administration agent with persistent privileged access on affected machines.
AI Analysis
Technical Summary
The 'claw-subagent-service' npm package, when installed globally, registers a privileged Windows service running as LocalSystem without prompting the user. This service periodically checks for updates and silently installs newer versions, enabling persistent code execution. It connects to a vendor-controlled RongCloud IM backend to receive remote commands that can execute arbitrary shell scripts and AI-driven commands on the host. Additionally, it continuously exfiltrates session data, project and task metadata, and host identifiers to the vendor backend every 30 seconds. This combination of privileged persistence, silent self-updating, remote command execution, and data exfiltration constitutes a vendor-operated remote administration agent installed via npm, posing a significant security risk if the publisher account or IM backend is compromised.
Potential Impact
Compromise of the publisher's npm account or the vendor's IM backend allows attackers to gain immediate, unattended, and persistent privileged code execution on all machines where the package is installed. The attacker can execute arbitrary commands with LocalSystem privileges on Windows or equivalent user privileges on macOS, and continuously exfiltrate sensitive session and host data. This creates a high-risk scenario for remote takeover and data leakage.
Mitigation Recommendations
No official patch or remediation is indicated. Users should avoid installing or running the 'claw-subagent-service' package globally. If already installed, uninstall the package and remove the associated privileged service. Monitor for and block network connections to the vendor IM backend domain 'newsradar.dreamdt.cn'. Since no patch is available, remediation relies on removal and network controls.
Malicious code in claw-subagent-service (npm)
Description
The npm package 'claw-subagent-service' installs a privileged Windows service that runs as LocalSystem without user consent. It establishes a persistent remote-control channel via a vendor-controlled IM backend, enabling arbitrary command execution and continuous data exfiltration from the host. The service self-updates silently every six hours, fetching and executing new versions with elevated privileges. This behavior creates a vendor-operated remote administration agent with persistent privileged access on affected machines.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'claw-subagent-service' npm package, when installed globally, registers a privileged Windows service running as LocalSystem without prompting the user. This service periodically checks for updates and silently installs newer versions, enabling persistent code execution. It connects to a vendor-controlled RongCloud IM backend to receive remote commands that can execute arbitrary shell scripts and AI-driven commands on the host. Additionally, it continuously exfiltrates session data, project and task metadata, and host identifiers to the vendor backend every 30 seconds. This combination of privileged persistence, silent self-updating, remote command execution, and data exfiltration constitutes a vendor-operated remote administration agent installed via npm, posing a significant security risk if the publisher account or IM backend is compromised.
Potential Impact
Compromise of the publisher's npm account or the vendor's IM backend allows attackers to gain immediate, unattended, and persistent privileged code execution on all machines where the package is installed. The attacker can execute arbitrary commands with LocalSystem privileges on Windows or equivalent user privileges on macOS, and continuously exfiltrate sensitive session and host data. This creates a high-risk scenario for remote takeover and data leakage.
Mitigation Recommendations
No official patch or remediation is indicated. Users should avoid installing or running the 'claw-subagent-service' package globally. If already installed, uninstall the package and remove the associated privileged service. Monitor for and block network connections to the vendor IM backend domain 'newsradar.dreamdt.cn'. Since no patch is available, remediation relies on removal and network controls.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-3757
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a73851abf8831d5394ef027
Added to database: 08/05/2026, 18:46:50 UTC
Last enriched: 08/05/2026, 23:33:45 UTC
Last updated: 09/10/2026, 17:39:16 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.