Open-source atomic malware analysis

Analyze another

clawtrl-wallet 1.5.1

NPM
Verdict: SUSPICIOUS
“Crypto wallet for AI agents on OpenClaw and Hermes — ERC-8128 signing, x402 payments, transfers on Base”
AI Downloads and executes remote shell script
Mal-ecule
H₄(Cm₅DbF₃Po₂)Md₂(InPa₂)
Size 2.8 KB download
First seen 7 hours ago
Analyzed 6 hours ago
Package pkg:npm/[email protected]
Ecosystem javascript
Also detected by osv+4 more

Loading file contents…

Loading traits…

Identity

SHA-256 6d54a94372572f4c45d3003a041e610c5530c64131c11fe7898a46f4fafbb7c3
Canonical SHA-256 000a60647bc4cd822e9469d2d45c099df90706292cad6feb10920e0cf56ce1e7
Filename clawtrl-wallet-1.5.1.tgz
Package clawtrl-wallet
Version 1.5.1
PURL pkg:npm/[email protected]

Origin

Source forager
Feed github-advisories
Ecosystem javascript
Domain npmjs.org
URL https://registry.npmjs.org/clawtrl-wallet/-/clawtrl-wallet-1.5.1.tgz

Timeline

First seen 5 Aug 2026 22:44 UTC
First analyzed 5 Aug 2026 23:52 UTC
Last analyzed 5 Aug 2026 23:52 UTC
Last updated 5 Aug 2026 23:52 UTC

Labeling

Label bad
Label source forager
Traits version b5ca8