logo

GitHub 'OpenClaw Deployer' Repo Delivers Trojan Instead

ID: 7062dc67-31c8-5488-8af3-b4c970f5b17c

STIX ID: report--7062dc67-31c8-5488-8af3-b4c970f5b17c

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-03-24

Date Updated: 2026-04-22

Author: Elizabeth Montalbano

...
...

Netskope Threat Labs uncovered "TroyDen's Lure Factory," a large-scale campaign distributing 300+ Trojanized GitHub packages (posing as OpenClaw deployers, game cheats, trackers, scripts, and more) that embed a LuaJIT-based Trojan. The malware uses a renamed Lua runtime paired with an encrypted script and anti-analysis tricks (including an extreme sleep delay and multi-file activation) to bypass automated detection, then captures desktop screenshots, collects geolocation and credentials, and exfiltrates data to a C2 in Frankfurt, creating a serious software supply-chain and credential-theft risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.