OpenClaw's supply chain extends far beyond a single application. The ClawHub marketplace, which hosts 10,700+ agent skills, has become a distribution channel for malware, credential theft, and persistent backdoors. Snyk's ToxicSkills audit of 3,984 skills found that 36.82% — 1,467 packages — cont...
"ClawHub is the npm registry for AI agents — with all the same problems, except the blast radius is your entire machine." — Snyk ToxicSkills Research Team, February 2026
OpenClaw's supply chain extends far beyond a single application. The ClawHub marketplace, which hosts 10,700+ agent skills, has become a distribution channel for malware, credential theft, and persistent backdoors. Snyk's ToxicSkills audit of 3,984 skills found that 36.82% — 1,467 packages — contained at least one security flaw. 534 had critical-level issues. 76 were confirmed malicious payloads. The Koi Security-identified ClawHavoc campaign accounted for 1,184 malicious skills alone, with one threat actor uploading 677 packages. The barrier to entry for publishing: a GitHub account seven days old and a Markdown file.
This is not a bug. It is the architecture functioning as designed. Skills execute with the same OS-level privileges as the OpenClaw process. MCP servers extend the attack surface through additional integration points. The AI agent itself can write new skills, creating a self-modifying system where the line between tool and threat dissolves. On February 17, 2026, a separate supply chain attack compromised the Cline CLI npm package, using a stolen publish token to silently install OpenClaw on approximately 4,000 developer machines — demonstrating that the contagion spreads beyond OpenClaw's own ecosystem.
ClawHub launched as an open marketplace for OpenClaw skills — packaged sets of instructions that define how the AI agent performs tasks. By mid-February 2026, the registry contained 10,700+ skills. The publishing requirements: a SKILL.md Markdown file and a GitHub account at least one week old. No code signing. No static analysis. No manual review. No sandbox.
Snyk's ToxicSkills study, published February 5, 2026, scanned 3,984 skills from ClawHub and skills.sh — the largest publicly available corpus of agent skills. The findings:
VirusTotal's independent analysis, using Gemini 3 Flash to perform security-focused analysis of skill packages, scanned more than 3,016 skills. Hundreds showed malicious characteristics. A single threat actor using the handle "hightower6eu" published 314 skills, all flagged as malicious.
Bitdefender placed the total count of malicious packages at approximately 900, representing roughly 20% of the ecosystem at the time of analysis.
These numbers describe a registry where between one in five and one in three packages pose a security risk. For comparison, the npm registry — which has faced its own supply chain crises — has never seen compromise rates approaching this percentage.
The ClawHavoc campaign, first detected on January 27, 2026, and surging on January 31, used a multi-layered attack strategy. According to Koi Security's analysis, the malicious skills followed several patterns:
Typosquatting. Skills named better-polymarket, polymarket-all-in-one, and solana-wallet-tracker mimicked legitimate tools. Documentation appeared professional. Functionality appeared real.
Fake prerequisites. 335 skills instructed users to run terminal commands under the guise of "fixing the environment." Those commands installed Atomic Stealer (AMOS), a commodity macOS infostealer available on criminal marketplaces for $500–$1,000 per month.
Reverse shells. Functional-looking skills hid backdoor code that opened reverse shell connections to attacker-controlled servers.
Credential exfiltration. Skills silently uploaded the contents of ~/.clawdbot/.env — which stores API keys, OAuth tokens, and integration credentials — to external webhook endpoints.
Target data included exchange API keys, wallet private keys, SSH credentials, browser passwords, and bot configuration files. One attacker uploaded 677 packages in a single campaign.
The most architecturally significant finding from the ClawHavoc analysis: 91% of malicious skills included prompt injection. These skills did not merely contain malicious code — they embedded hidden instructions that manipulated the AI agent itself.
According to Snyk's research, the injected prompts caused OpenClaw to:
curl commands to download additional payloadsThis represents a category of attack that has no precedent in traditional software supply chains. An npm package cannot convince Node.js to ignore its own security policies. A malicious skill can convince an AI agent to disregard its safety instructions.
Penligent's research demonstrated that attackers can modify OpenClaw's SOUL.md — the persistent context file that defines the agent's identity and behavioral boundaries — to introduce long-term behavioral changes. Once the memory file is compromised, the attack persists across sessions and restarts. The agent has been, in Penligent's terminology, "cognitively rootkitted."
As NIST's CAISI framework defines it, this constitutes "agent hijacking" — the lack of separation between trusted instructions and untrusted data allows attackers to redirect the agent's objective.
Beyond deliberately malicious skills, Snyk identified a separate problem: skills that leak credentials through negligence rather than malice.
283 skills (7.1% of the registry) contained instructions that exposed API keys, passwords, and personal data. Popular, functional skills like moltyverse-email and youtube-data instructed AI agents to handle secrets in ways that passed them through the LLM's context window and output logs in plaintext.
When a skill instructs the agent to "use this API key," the model stores the key in its conversation history. That history can be leaked to the model provider — Anthropic, OpenAI, or others — through standard API calls. The credential is no longer contained on the user's machine; it exists in a third-party inference pipeline.
This architectural flaw means that even legitimate, well-intentioned skills can transform OpenClaw into a credential exfiltration vector — not by design, but by the fundamental way LLM-based agents process information.
The Model Context Protocol (MCP) provides a standardized interface for connecting AI models to external tools and data sources. OpenClaw supports MCP servers as an extension mechanism alongside skills. Each MCP server represents an additional attack surface.
CVE-2025-6514, a critical OS command-injection vulnerability in mcp-remote — a popular OAuth proxy for MCP servers with over 437,000 downloads — allowed malicious MCP servers to achieve remote code execution on client machines. The vulnerability effectively turned unpatched installations into supply chain backdoors.
Three additional vulnerabilities (CVE-2025-68145, CVE-2025-68143, CVE-2025-68144) in Anthropic's own Git MCP server enabled remote code execution via prompt injection, including path validation bypass and argument injection.
Invariant Labs demonstrated that a malicious MCP server could silently exfiltrate a user's entire WhatsApp message history by combining tool poisoning with a legitimate MCP server. The attack required no special permissions — it operated within the standard MCP trust model.
Users pull community-contributed MCP servers from open repositories with the same absence of verification that characterizes ClawHub. MCP tool poisoning — where malicious metadata manipulates the AI agent's behavior — represents what multiple security firms describe as a new, AI-native supply chain vector that traditional security tools do not monitor.
OpenClaw can write its own skills. When it encounters a task it does not know how to perform, it generates the code required to accomplish it. Cisco's security analysis described this as the agent producing "vibe code" — functional but unreviewed scripts that execute with the agent's full system privileges.
This capability collapses the distinction between user, developer, and runtime. The AI agent is simultaneously:
A prompt injection attack that modifies the agent's behavior can cause it to write and execute malicious skills autonomously. The attacker does not need to publish a package to ClawHub. The compromised agent generates the payload locally, from memory that has been poisoned through a prior interaction.
Microsoft's security blog, published February 19, 2026, stated the core risk plainly: self-hosted agents combine "untrusted code and untrusted instructions into a single execution loop that runs with valid credentials." Their recommendation: assume compromise is possible, isolate the runtime, and be prepared to rebuild without delay.
On February 17, 2026, at 3:26 AM PT, an unauthorized party published Cline CLI version 2.3.0 to the npm registry using a compromised publish token. The package contained a modified package.json with one addition:
"postinstall": "npm install -g openclaw@latest"
For approximately eight hours, every developer who installed Cline CLI received an unauthorized OpenClaw installation. Approximately 4,000 downloads occurred before the package was deprecated at 11:30 AM PT. The compromised token was revoked and Cline released version 2.4.0 with OIDC-based publishing via GitHub Actions.
The incident demonstrated that OpenClaw's supply chain risk extends beyond its own ecosystem. A compromised dependency in an unrelated tool can install OpenClaw — with its full system access capabilities — on developer machines without consent. The attack chain is recursive: a supply chain compromise installs a tool that itself has supply chain vulnerabilities, each layer amplifying the risk of the one below it.
The complete trust chain in an OpenClaw deployment operates as follows:
Any single link in this chain that breaks compromises every link above it. A malicious npm package inside a skill inside OpenClaw has the same access as OpenClaw itself: email, calendar, messaging, file system, shell commands, browser, GitHub tokens, Gmail API keys, Slack tokens.
Each of OpenClaw's 50+ integrations — Gmail, GitHub, Spotify, Obsidian, Twitter, and others — represents an OAuth token or API key stored locally. A supply chain compromise at any depth can exfiltrate all of them. Memory files stored in plain Markdown — containing daily notes, preferences, relationships, financial details — are readable by any process with disk access.
Following the security crisis, three security tools emerged:
SecureClaw, published by Adversa AI on February 16, 2026, provides 55 audit checks for OpenClaw installations and includes hardening modules. It operates as both a plugin and a skill, aligning with OWASP and MITRE agentic AI frameworks.
ClawSec, created by Prompt Security and published by SentinelOne, functions as a "skill-of-skills" — a security layer that wraps agents in drift detection, automated audits, and skill integrity verification.
ClawShield offers audit commands and auto-fix capabilities for common configuration issues.
These tools arrived weeks after the crisis began. They operate within the same architectural constraints they attempt to mitigate: they are skills that run inside the agent they are trying to protect, with no higher-privilege isolation boundary.
Aikido Security's assessment, titled "Why Trying to Secure OpenClaw is Ridiculous," stated the fundamental problem: "As long as AI agents need to process untrusted content to be useful, prompt injection remains unfixable." The security tools reduce low-effort attacks. They cannot address the architectural absence of privilege separation.
OpenClaw itself integrated VirusTotal scanning to hash skills and compare them against known malicious samples. The project's maintainers acknowledged it is "not a silver bullet" and that skills using "cleverly concealed prompt injection payloads may slip through the cracks." Signature-based detection addresses known threats. The ClawHavoc campaign demonstrated that novel payloads — prompt injections embedded in Markdown files — bypass traditional scanning entirely.
The supply chain problem in OpenClaw is not a collection of individual vulnerabilities to be patched. It is the natural consequence of an architecture that grants unrestricted system access to an AI agent, allows that agent to load arbitrary code from an unvetted marketplace, and permits it to write and execute its own code without review.
Traditional software supply chain attacks — SolarWinds, the event-stream npm incident, the ua-parser-js compromise — required human attackers to craft and maintain malicious code. OpenClaw's architecture introduces a new variable: an AI agent that can be manipulated through language into becoming the attacker. The supply chain does not end at the code. It extends through every piece of text the agent processes, every webpage it reads, every email it receives.
Microsoft's guidance — assume compromise, isolate, constrain, monitor, prepare to rebuild — is the only defensible posture for organizations that proceed with deployment. For the 300,000–400,000 individuals running OpenClaw on personal machines with their full digital lives accessible, that guidance arrives after the architecture has already been trusted.