Skip to main content

Malicious code in claw-subagent-service (npm)

0
Critical
Published: 05/14/2026 (05/14/2026, 19:25:16 UTC)
Source: GCVE Database
Product: claw-subagent-service

Description

The npm package 'claw-subagent-service' installs a privileged Windows service that runs as LocalSystem without user consent. It establishes a persistent remote-control channel via a vendor-controlled IM backend, enabling arbitrary command execution and continuous data exfiltration from the host. The service self-updates silently every six hours, fetching and executing new versions with elevated privileges. This behavior creates a vendor-operated remote administration agent with persistent privileged access on affected machines.

Affected software

npmghsa
claw-subagent-service
Affected versions
=0.0.80=0.0.91=0.0.120=0.0.113=0.0.99=0.0.101=0.0.116=0.0.122=0.0.105=0.0.138=0.0.108=0.0.102=0.0.109=0.0.140=0.0.136=0.0.130=0.0.117=0.0.110=0.0.141=0.0.137=0.0.114=0.0.151=0.0.149=0.0.146=0.0.162=0.0.170=0.0.177=0.0.156=0.0.161=0.0.168=0.0.164=0.0.160=0.0.153=0.0.179=1.4.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 23:33:45 UTC

Technical Analysis

The 'claw-subagent-service' npm package, when installed globally, registers a privileged Windows service running as LocalSystem without prompting the user. This service periodically checks for updates and silently installs newer versions, enabling persistent code execution. It connects to a vendor-controlled RongCloud IM backend to receive remote commands that can execute arbitrary shell scripts and AI-driven commands on the host. Additionally, it continuously exfiltrates session data, project and task metadata, and host identifiers to the vendor backend every 30 seconds. This combination of privileged persistence, silent self-updating, remote command execution, and data exfiltration constitutes a vendor-operated remote administration agent installed via npm, posing a significant security risk if the publisher account or IM backend is compromised.

Potential Impact

Compromise of the publisher's npm account or the vendor's IM backend allows attackers to gain immediate, unattended, and persistent privileged code execution on all machines where the package is installed. The attacker can execute arbitrary commands with LocalSystem privileges on Windows or equivalent user privileges on macOS, and continuously exfiltrate sensitive session and host data. This creates a high-risk scenario for remote takeover and data leakage.

Mitigation Recommendations

No official patch or remediation is indicated. Users should avoid installing or running the 'claw-subagent-service' package globally. If already installed, uninstall the package and remove the associated privileged service. Monitor for and block network connections to the vendor IM backend domain 'newsradar.dreamdt.cn'. Since no patch is available, remediation relies on removal and network controls.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-3757
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a73851abf8831d5394ef027

Added to database: 08/05/2026, 18:46:50 UTC

Last enriched: 08/05/2026, 23:33:45 UTC

Last updated: 09/10/2026, 17:39:16 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses