OpenClaw, an autonomous AI agent platform with a community “skills” marketplace, integrated VirusTotal scanning to check skills uploaded to ClawHub after security firms and researchers highlighted that the ecosystem is being abused to distribute malicious components. Reporting described attackers leveraging trust in marketplaces and “skills” registries to seed malware, and noted active discussion in criminal forums about using OpenClaw skills to support illicit activity (e.g., botnet operations). Separate research also pointed to rapid growth in lookalike packages (e.g., “claw” on npm/PyPI), reinforcing concerns that the surrounding supply chain is being targeted as the platform’s popularity increases.
Enterprise risk assessments emphasized that many organizations are granting OpenClaw privileged access quickly (including via shadow deployments), creating high-impact failure modes if a host or skill is compromised—potentially exposing API keys, OAuth tokens, and sensitive conversations. OpenClaw acknowledged that VirusTotal-based scanning is not sufficient to detect non-signature threats such as prompt-injection-driven malicious behavior or skills that use natural language instructions to induce harmful actions, leaving material residual risk even with malware scanning in place.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
In March 2026, attackers published a fake 'DeepSeek-Claw' OpenClaw skill on GitHub to compromise developers and AI-driven workflows. Zscaler ThreatLabZ said the malicious plugin used hidden commands and npm lifecycle scripts to deliver Remcos RAT on Windows or GhostLoader across Windows, macOS, and Linux for credential and data theft.
OpenClaw integrated Google's VirusTotal to scan skills uploaded to ClawHub for known malware. The company acknowledged the control would not catch natural-language malicious behavior or prompt-injection payloads without signatures.
By early February 2026, security reporting highlighted that OpenClaw's skills architecture had been exploited by ClawHavoc, with malicious skills appearing in the ClawHub registry. Researchers also noted forum discussions about using OpenClaw skills for botnet activity and a rise in potentially typosquatting 'claw'-named packages on npm and PyPI.
On February 5, 2026, VirusTotal published a deeper analysis of five malicious OpenClaw skills, showing how the ecosystem could be abused for reverse shells, SSH key injection, .env credential theft, scheduler-based propagation, and persistent prompt-file implants. The report framed third-party skills as a supply-chain attack vector and recommended mitigations including sandboxing, default-deny egress, provenance checks, and replacing long-lived .env secrets with short-lived scoped tokens.
On February 2, 2026, VirusTotal reported that hundreds of OpenClaw skills were malicious among more than 3,016 analyzed packages, describing the ecosystem as a malware delivery channel. The report linked ClawHub user 'hightower6eu' to 314 malicious skills and detailed a 'Yahoo Finance' skill that delivered an Atomic Stealer (AMOS) variant via unsafe setup instructions.
On January 30, 2026, Gartner reported that 53% of Noma's enterprise customers had granted OpenClaw privileged access over a single weekend. Gartner called the tool an unacceptable cybersecurity liability and recommended immediately blocking OpenClaw downloads and traffic.
In late January 2026, OpenClaw's popularity rapidly increased, surpassing 150,000 GitHub stars. The fast uptake helped drive widespread enterprise experimentation and deployment.
OpenClaw launched in November 2025 and subsequently changed names twice because of trademark disputes. The project's popularity continued to grow despite the rebranding.
In April 2026, Kaspersky reported finding 24 accounts distributing more than 600 malicious OpenClaw skills through the sharing hub. The disclosure showed that malicious skill distribution continued at scale even after preliminary scanning measures such as VirusTotal and NVIDIA SkillSpector were adopted.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcethehackernews.com
Open sourcecsoonline.com
Open sourceblog.virustotal.com
Open sourceblog.virustotal.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.