ClawHavoc is a coordinated supply-chain poisoning campaign targeting the ClawHub marketplace for the OpenClaw AI agent framework. The operation involved the mass publication of malicious AI-agent “skills” disguised as legitimate utilities, including cryptocurrency tools, productivity integrations, finance-related helpers, social-media tools, developer utilities, and content summarizers. The campaign is notable for abusing an emerging agentic AI software ecosystem in a manner analogous to package-repository compromise, while also exploiting the elevated permissions and autonomous execution paths available to AI agents. The operators used professional-looking documentation and social-engineering lures to persuade users to execute malicious setup steps. Observed techniques included prerequisite instructions directing Windows users to retrieve password-protected archives, macOS users to run obfuscated shell commands that fetched second-stage payloads, and embedded prompt-injection content intended to coerce agents or users into unsafe command execution. Follow-on activity also used deceptive comments on popular marketplace entries to redirect victims to attacker-controlled installation instructions, indicating persistence and adaptation after initial exposure. Payloads associated with ClawHavoc included information stealers, backdoors, reverse-shell functionality, and direct secret-exfiltration logic. Atomic Stealer (AMOS) was a confirmed macOS payload and was used to steal browser data, keychain contents, cryptocurrency-wallet data, Telegram artifacts, SSH material, history files, documents, and other sensitive information. Additional malicious skills were designed to exfiltrate OpenClaw bot configuration secrets and API tokens from environment files, while others embedded hidden operating-system command execution or webhook-based theft inside otherwise plausible functionality. The campaign scaled rapidly, with reporting linking hundreds of malicious skills to a single coordinated operation and later identifying well over 900 malicious listings overall. A prolific publisher account was associated with a large share of the malicious uploads, alongside numerous additional uploader identities. ClawHavoc has been assessed by some researchers as potentially Chinese in origin, but attribution remains unconfirmed. The actor’s behavior is consistent with financially motivated cybercrime focused on credential theft, cryptocurrency theft, and broader information theft rather than espionage or destructive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Supply-chain poisoning of the ClawHub marketplace for the OpenClaw AI agent framework via hundreds of trojanized “Skills” and follow-on comment-based social engineering, leading victims to execute obfuscated commands/downloads that install information stealers (notably Atomic Stealer on macOS), reverse shells, and exfiltration tooling to steal credentials, crypto wallet data, and AI/bot configuration secrets (e.g., ~/.clawdbot/.env tokens).
Coordinated malicious supply-chain campaign abusing OpenClaw’s ClawHub skill marketplace by uploading large volumes of trojanized “skills” containing prompt-injection instructions and/or data-exfiltration logic, including commands that fetch and execute remote payloads and beacon to shared infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.