T06 · System Persistence
- Location
scripts/bootstrap_tbot_launchagent.sh:78- Finding
Persistent macOS LaunchAgent Installed and Automatically Restarted
- Content
View full analysis
RunAtLoad KeepAlive StandardOutPath${OUT_DIR}/tbot.stdout.log StandardErrorPath${OUT_DIR}/tbot.stderr.log WorkingDirectory${OUT_DIR} PLIST launchctl bootout "gui/$(id -u)/${LABEL}" >/dev/null 2>&1 || true launchctl bootstrap "gui/$(id -u)" "$PLIST_PATH" launchctl kickstart -k "gui/$(id -u)/${LABEL}" ``` ### Technical Analysis The bootstrap script creates and activates a macOS LaunchAgent configured with both `RunAtLoad` and `KeepAlive`. The agent therefore starts when the user logs in and is automatically restarted when it exits. This persistence is explicitly documented and is directly related to maintaining a Teleport Machine ID. Nevertheless, it creates a cross-session execution mechanism. The script also replaces any existing LaunchAgent using the fixed `com.openclaw.tbot` label without first confirming that the existing service belongs to this project. The persisted command uses the path returned by `command -v tbot` at installation time. If an attacker can influence the invoking environment or place a malicious `tbot` earlier in `PATH`, that executable path can be stored in the LaunchAgent. ### Attack Path 1. An attacker influences the user's `PATH` or places a malicious executable named `tbot` in a higher-priority writable directory. 2. The user runs the bootstrap script. 3. `command -v tbot` resolves the attacker-controlled executable. 4. The resulting path is written into `~/Library/LaunchAgents/com.openclaw.tbot.plist`. 5. The script immediately loads and starts the LaunchAgent. 6. The malicious executable subsequently runs at login and is restarted through `KeepAlive`. ### Impact Assessment Th ...[truncated 445 chars]- Remediation
View remediation
