T07 · Tool Hijacking and Spoofing
- Location
apply.sh:113- Finding
Injection of Skill-Controlled Code into Trusted OpenClaw Application Bundles
- Content
View full analysis
> "$DIST_JS" if ! grep -q "$MARKER" "$DIST_JS"; then red "✗ Patch append failed at $ROOT, restoring." cp "$DIST_JS.milly.bak" "$DIST_JS" continue fi # Cache-bust: rename and update index.html if [[ -f "$INDEX_HTML" ]]; then if [[ "$ENTRY_NAME" == *.milly-*.js ]]; then dim "→ already cache-busted ($ENTRY_NAME)" else BUST="milly-$(date +%s | tail -c 6)" NEW_NAME="${ENTRY_NAME%.js}.${BUST}.js" NEW_PATH="$ASSETS/$NEW_NAME" mv "$DIST_JS" "$NEW_PATH" [[ -f "$DIST_JS.milly.bak" ]] && mv "$DIST_JS.milly.bak" "$NEW_PATH.milly.bak" [[ -f "$INDEX_HTML.milly.bak" ]] || cp "$INDEX_HTML" "$INDEX_HTML.milly.bak" sed -i.tmp "s|$ENTRY_NAME|$NEW_NAME|g" "$INDEX_HTML" && rm -f "$INDEX_HTML.tmp" green "✓ Patched + cache-busted: $ENTRY_NAME → $NEW_NAME" fi else yellow "⚠ index.html not found at $INDEX_HTML; cache may persist." fi ``` The injected payload subsequently runs inside the OpenClaw UI and observes its document: ```javascript observer.observe(document.body, { subtree: true, childList: true }); mountWidget(); ``` ### Technical Analysis The installation script directly appends Skill-controlled JavaScript to OpenClaw's compiled entry bundle. It then renames that bundle and rewrites `index.html` so the trusted application loads the modified file. This is a tool-hijacking pattern because an existing trusted application artifact is modified to execute additional logic under the appearance and origin of the original OpenClaw UI. Although the audited payload implements the documented notification feature and no malicious network access, credential theft, or exfiltra ...[truncated 1923 chars]- Remediation
View remediation
