Security researchers reported that the OpenClaw self-hosted AI assistant ecosystem is being abused for malware distribution via ClawHub, a public registry for third-party “skills.” At least 14 malicious skills uploaded over a short window masqueraded as crypto trading/wallet automation tools, but were designed to trick users into executing obfuscated setup commands that fetch and run remote scripts. Because OpenClaw skills are installed as executable code (not sandboxed) with access to local files and network resources, successful installs can enable credential theft and cryptocurrency wallet compromise on Windows and macOS, and one malicious listing reportedly reached prominent placement before removal, increasing the likelihood of accidental installs.
Separate reporting also highlighted a related risk: a 1-click remote code execution (RCE) issue affecting OpenClaw/Moltbot/ClawdBot was discussed in the security community, indicating that the same ecosystem is facing both supply-chain style extension abuse and potential direct exploitation paths. Organizations allowing developer or power-user adoption of OpenClaw should treat third-party skills as untrusted software, restrict installation sources, and monitor for social-engineering patterns such as “copy/paste this one-liner” installers that retrieve code from external servers—especially when tied to cryptocurrency-themed lures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
After automated scanning was introduced, researchers observed attackers shifting to benign-looking SKILL.md files that redirected users to external malware via fake OpenClawCLI installation pages and obfuscated commands. The change let trojanized skills appear clean to file-based scanners while still delivering payloads from attacker infrastructure.
OpenClaw announced a partnership with VirusTotal to automatically scan every skill uploaded to ClawHub using SHA-256 fingerprinting, lookups, and Code Insight analysis. Malicious skills would be blocked and suspicious ones labeled, though maintainers noted the system would not fully stop instruction-only social-engineering attacks.
Zenity disclosed a proof-of-concept attack in which malicious content delivered through trusted integrations could cause OpenClaw to create an attacker-controlled integration such as a Telegram bot. Once established, the attacker could use the new channel to exfiltrate files, delete data, or deploy additional tooling like Sliver.
Snyk reported that 283 OpenClaw skills, about 7.1% of those examined, exposed sensitive credentials by placing secrets into LLM context or plaintext logs. The findings showed that the marketplace risk extended beyond overt malware to systemic insecure secret handling.
As part of its response to the ClawHub abuse, VirusTotal added OpenClaw skill support to its Code Insight tooling to analyze package behavior. The enhancement was intended to help identify malicious skills and unsafe implementations in the ecosystem.
VirusTotal analyzed roughly 3,000 OpenClaw skills and reported that hundreds showed malicious characteristics, including exfiltration, remote-control, and malware-installation behavior. It highlighted publisher hightower6eu as a major source of malicious uploads and showcased examples delivering Windows trojans and AMOS on macOS.
The project disclosed three high-impact security advisories in a three-day span, including a one-click remote code execution flaw and two command-injection vulnerabilities. These disclosures added to concerns that the platform itself, not just its skill ecosystem, had serious security weaknesses.
By early February, multiple reports described the campaign as having grown to hundreds of malicious skills across ClawHub and GitHub, with counts ranging from 230 to more than 380. The activity was characterized as a supply-chain style malware operation targeting OpenClaw users with credential and crypto theft.
In response to the malicious-skill findings, OpenClaw creator Peter Steinberger added a reporting feature to ClawHub that automatically hides a skill after more than three unique reports. The change was presented as an immediate mitigation while abuse of the marketplace continued.
Koi Security audited 2,857 ClawHub skills and identified 341 malicious entries, including 335 linked to a campaign it named ClawHavoc. The malicious skills delivered AMOS-like malware, keyloggers, reverse shells, and credential exfiltration payloads while impersonating legitimate utilities.
1Password reported that the top-downloaded "Twitter" skill on ClawHub used ClickFix-style instructions to trick users into running an obfuscated command that fetched and executed macOS infostealer malware. The post framed OpenClaw skills as a new supply-chain attack surface where markdown instructions can act as malware delivery.
OpenSourceMalware published analysis of a large ClawHub/GitHub campaign, reporting hundreds of malicious skills tied to shared infrastructure at 91.92.242.30 and largely attributed to the user hightower6eu. The report described Windows and macOS infostealer delivery, including likely NovaStealer activity on macOS.
Researchers later reported that at least 14 malicious skills were uploaded to the public ClawHub registry between January 27 and 29. Some reached prominent placement on ClawHub, increasing the chance of accidental installation before removal.
A coordinated campaign started publishing trojanized OpenClaw/ClawdBot/Moltbot skills in two waves on ClawHub and GitHub, largely masquerading as cryptocurrency and automation tools. The activity began on January 27 and used social engineering to push users toward external malware installers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcesocket.dev
Open sourcethehackernews.com
Open sourcereddit.com
Open sourcetomshardware.com
Open sourcehelpnetsecurity.com
Open sourceopensourcemalware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.