GitHub 'OpenClaw Deployer' Repo Delivers Trojan Instead
ID: 7062dc67-31c8-5488-8af3-b4c970f5b17c
STIX ID: report--7062dc67-31c8-5488-8af3-b4c970f5b17c
Feed Name: Dark Reading
Netskope Threat Labs uncovered "TroyDen's Lure Factory," a large-scale campaign distributing 300+ Trojanized GitHub packages (posing as OpenClaw deployers, game cheats, trackers, scripts, and more) that embed a LuaJIT-based Trojan. The malware uses a renamed Lua runtime paired with an encrypted script and anti-analysis tricks (including an extreme sleep delay and multi-file activation) to bypass automated detection, then captures desktop screenshots, collects geolocation and credentials, and exfiltrates data to a C2 in Frankfurt, creating a serious software supply-chain and credential-theft risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
