OpenClaw Trap: AI-Assisted LuaJIT Malware Factory Targeting Developers & Gamers via GitHub Supply Chain — Threadlinqs Intelligence
As of 2026-05-30, OpenClaw Trap: AI-Assisted LuaJIT Malware Factory Targeting Developers & Gamers via GitHub Supply Chain is a high-severity supply chain threat attributed to TroyDen (N/A), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-0275 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: TroyDen · N/A · FINANCIAL
Netskope Threat Labs identified TroyDen’s Lure Factory, an AI-assisted malware campaign operating across 300+ GitHub delivery packages including a trojanized OpenClaw Docker deployer, phone trackers,
TroyDen’s Lure Factory is a sophisticated, AI-assisted malware distribution campaign discovered by Netskope Threat Labs in March 2026. The operation leverages over 300 trojanized GitHub repositories across multiple simultaneous campaigns targeting distinct victim demographics: software developers (via a fake OpenClaw Docker deployer), mobile users (via phone tracker utilities promoted on Telegram), and gamers (via fishing game cheat menus and Roblox script engines).
The campaign’s hallmark is its industrial-scale use of AI-generated content to create convincing repository READMEs, documentation, and github.io landing pages. Repositories are further legitimized through manufactured GitHub stars and forks, creating an illusion of community trust. The operator persona TroyDen has been active on Telegram since at least June 2025, promoting various lure packages.
The malware payload employs a two-component LuaJIT 2.1.0-beta3 loader architecture. The first component (Payload 0) performs environmental reconnaissance and sandbox evasion, while the second component (Payload 1) delivers the final credential-stealing payload. Both components are obfuscated using the Prometheus Lua Obfuscator, which encrypts strings and employs a virtual machine layer to resist static analysis.
The loader’s anti-analysis arsenal is extensive: it queries for debugger presence, checks system RAM to detect low-memory sandbox environments, measures system uptime to identify freshly-booted analysis VMs, enumerates SeDebugPrivilege to detect analyst tooling, queries the computer name for known sandbox identifiers, and implements a catastrophic 29,000-year sleep delay (approximately 9.15 x 10^11 seconds) designed to defeat timed sandbox detonation systems.
Upon successful evasion checks, the loader performs a geolocation preflight via ip-api.com to implement geographic fencing, captures a full 24-bit BMP desktop screenshot for victim profiling, disables WinINet proxy auto-detection through 4 registry writes to ensure reliable C2 communication, and establishes encrypted C2 beaconing. The C2 infrastructure consists of 8+ nodes hosted on SERVHOST-AS (ASN 207957) in Frankfurt, Germany, behind nginx load balancing. Communication uses PUT requests with multipart/form-data encoding for data exfiltration and receives encrypted task blobs via JSON objects.
The final payloads include LummaStealer and Redline Stealer variants capable of harvesting browser credentials, cryptocurrency wallet data, two-factor authentication tokens, and DPAPI-protected secrets. Persistence is achieved through Windows Scheduled Tasks named WindowsErrorReporting_<LoaderID> and file staging in %APPDATA% and %USERPROFILE%\Pictures directories.
Four GitHub accounts have been identified as active delivery vectors: AAAbiola (openclaw-docker campaign, active), mikenob39wang (phone-tracker campaign, active), B3RZ3RK (fishing-planet-enhanced-menu campaign, active), and coteyn (seeder account, dormant since December 4, 2025). The campaign represents a significant evolution in supply chain attacks, combining AI-assisted social engineering at scale with sophisticated multi-stage malware delivery.
Weaknesses (CWE)
CWE-506, CWE-494, CWE-829
Target sectors: technology, gaming, cryptocurrency, software-development, education
Target regions: Global, North America, Europe, Asia Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1195, T1199, T1204, T1059, T1218, T1053, T1547, T1027, T1036, T1497