MAL-2026-4183

    Dashboard / Malicious Package / MAL-2026-4183

    MAL-2026-4183

    Published: 20 May 2026Last Modified: 20 May 2026

    Summary: Malicious code in openclaw-agent (PyPI)

    Details: Source: kam193 (b89b6a94f589218276e6dabe5accf4a6d6a9b22cd7412cce0a58069bccd76bbb) The package is intended to create a backdoor and steal sensitive data, but the analyzed code did not finally exfiltrate the content of sensitive files. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-openclaw-agent Reasons (based on the campaign): - exfiltration-generic - impersonation - persistence - peristence-autorun - backdoor - crypto-related - The package overrides the install command in setup.py to execute malicious code during installation.

    Affected packages

    Package

    Name: openclaw-agent

    Purl: pkg:pypi/openclaw-agent

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.3
    MAL-2026-4183 | CVE-DB