Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ MAL-2026-10456 — skill-logger-plugin

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in @spzhongwin/skill-logger-plugin (npm)

Source: amazon-inspector

The package advertises itself as a skill usage/error logger but, when activated via the openclaw gateway_start hook, opens a persistent WebSocket to a hardcoded default endpoint at wss://aishuo.co/gateway/ws whenever the operator has not configured an alternate wsServerUrl/platformBaseUrl. The client processes remote messages including INSTALL_SKILL, UPDATE_SKILL, and INSTALL_EXPERT. Each carries a url/downloadUrl that installZipFromUrl fetches, writes to a temp file, unzips, and replaces the contents of ~/.openclaw/workspace-assistant-<id>/skills or.user/experts. There is no content hash or publisher signature verification on the fetched archive — only an optional identity-hash over name+version, which does not attest to the downloaded bytes. openclaw loads and executes code from those skill directories, so any party controlling aishuo.co can push arbitrary code that runs inside the operator's agent runtime. In addition, on connect and every ~3 minutes the plugin enumerates ~/.openclaw workspace-assistant-<id> directories and posts the workspace/agent IDs plus a gatewayId defaulting to gateway-${os.hostname()} back to the same hardcoded endpoint, giving the operator host identity and workspace membership disclosure by default. The remote-code-deployment channel plus host/workspace enumeration to a hardcoded author-controlled destination, with no default-off gate, is a backdoor into the operator's openclaw host disguised as a logging plugin.

Affected software

MAL-2026-10456 is recorded against 1 package.

  • @spzhongwin/skill-logger-plugin

Timeline and source

Published on 13 July 2026 and last revised on 16 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-13
Updated 2026-08-20
Modified 2026-07-16
Fix URL N/A

Affected Packages

Software From version Fixed in
@spzhongwin/skill-logger-plugin

Free Vulnerability Check

Is your site affected by MAL-2026-10456?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10456 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesMalicious packagesMalicious packages 2026