
Cyber Security
OpenClaw Malicious Skills Delivered Infostealers As ClawHub Tightened Security Screening
Updated on Thu, Aug 20, 2026
OpenClaw’s third-party skill ecosystem has emerged as a software supply-chain attack surface, with security researchers documenting malicious ClawHub packages that delivered infostealers, backdoors and other threats while exploiting the extensive permissions available to AI agents.
TL;DR
- Researchers found hundreds of malicious OpenClaw skills distributed through the ClawHub marketplace.
- Some delivered infostealers, backdoors and remote-access malware to Windows and macOS systems.
- Later malicious skills managed to evade marketplace security screening.
- OpenClaw has since strengthened ClawHub with VirusTotal, ClawScan and additional security auditing, while warning users to treat third-party skills as untrusted code.
Security researchers have documented multiple campaigns in which malicious OpenClaw skills were disguised as useful automation tools but instead directed users or their AI agents to download and execute malware.
OpenClaw is a self-hosted AI agent capable of executing shell commands, accessing files and making network requests. Its capabilities can be extended using third-party skills, many of which are distributed through the public ClawHub marketplace.
That flexibility also creates risk when an installed skill cannot be trusted.
Hundreds Of Malicious OpenClaw Skills Were Found
Koi Security disclosed the ClawHavoc campaign on February 1, after auditing all 2,857 skills then available on ClawHub.
Researchers initially identified 341 malicious skills, including 335 that appeared to belong to one coordinated campaign. Koi later updated its findings on February 16, saying the number had risen to 824 malicious skills as the marketplace expanded beyond 10,700 skills.
The malicious packages appeared across categories including browser automation, coding tools, social media integrations and PDF utilities.
VirusTotal separately reported that it had analyzed more than 3,000 OpenClaw skills, finding hundreds that displayed malicious characteristics.
Some skills appeared to offer harmless functions such as cryptocurrency analytics, financial tracking or social media tools. However, they instructed users to download and execute external files as part of their installation process.
In one case, Windows users were directed to download an executable that security vendors identified as malicious. On macOS, another installation process ultimately delivered a variant of Atomic Stealer, malware designed to steal passwords, browser cookies, stored credentials and cryptocurrency wallet information.
VirusTotal said the risk extended beyond conventional malicious binaries because the malware could be embedded in the workflow an AI agent was instructed to follow.
Researchers also documented techniques including reverse shells, SSH key injection, persistence mechanisms and instructions capable of modifying an agent's longer-term behavioral context.
Malicious Skills Later Bypassed Security Screening
The initial findings prompted ClawHub to introduce additional screening, but researchers subsequently found malicious skills that remained available.
Palo Alto Networks' Unit 42 said its investigation covering February through May identified five malicious skills that had remained unblocked despite security checks.
Two delivered macOS infostealers and communicated with command-and-control infrastructure, while another used an unusually large file to exceed analysis thresholds and evade both ClawScan and VirusTotal detection.
Unit 42 also identified two agent-specific threats designed to manipulate financial activity for the publisher's benefit.
One of the malicious campaigns discovered in May used the same general delivery approach as earlier ClawHavoc attacks but relied on different infrastructure and a different payload.
Unit 42 reported all five skills to ClawHub. OpenClaw subsequently banned the associated accounts and removed the packages.
Topics For More Insights
OpenClaw Strengthens ClawHub Security
ClawHub now incorporates multiple layers of security analysis before users install skills.
Its security audit system combines VirusTotal malware telemetry with ClawScan risk analysis and additional checks focused on risks such as prompt injection, credential exposure, unsafe execution, excessive permissions and context poisoning.
OpenClaw also lets users verify ClawHub skills before installation, with skill pages displaying security information from VirusTotal, ClawScan and static analysis.
However, OpenClaw itself cautions that automated screening should not remove the need for human scrutiny.
Its documentation explicitly tells users to treat third-party skills as untrusted code, read them before enabling them and use sandboxed environments for untrusted inputs or tools carrying greater risk.
ClawHub's security documentation also notes that VirusTotal results serve as malware telemetry rather than a complete guarantee that an artifact is safe.
The incidents highlight a growing challenge for agentic AI ecosystems. Unlike an ordinary software extension, an AI-agent skill may operate in an environment with access to files, credentials, terminals, network services and authenticated business applications.
That means a malicious skill can potentially abuse not only executable code but also the instructions the AI agent itself is trusted to follow.
First published on Thu, Aug 20, 2026
Enjoyed what you read? Great news – there’s a lot more to explore!
Dive into our content repository of the latest tech news, a diverse range of articles spanning introductory guides, product reviews, trends and more, along with engaging interviews, up-to-date AI blogs and hilarious tech memes!
Also explore our collection of branded insights via informative white papers, enlightening case studies, in-depth reports, educational videos and exciting events and webinars from leading global brands.
Head to the TechDogs homepage to Know Your World of technology today!
Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.
Loading comments...

