Researchers reported multiple campaigns abusing AI agent “skills” as a new supply-chain-like initial access vector. In one case, a malicious ClawHub skill (bob-p2p) masqueraded as a decentralized API marketplace and was promoted via the AI-agent social platform Moltbook; once installed, it caused agents to retain plaintext Solana private keys and execute transactions that bought worthless $BOB tokens while routing value to attacker-controlled infrastructure. Staiker researchers and analyst Dan Regalado highlighted that agent-to-agent collaboration, shared workflows, and dependency chains can enable lateral movement without direct human interaction, making the technique repeatable and scalable beyond crypto-wallet theft.
Separately, Trend Micro described a shift in Atomic macOS Stealer (AMOS) distribution from cracked software to malicious OpenClaw skills hosted across ClawHub, SkillsMP, and GitHub. The campaign used seemingly benign SKILL.md instructions to trick models/users into installing a fake prerequisite (“OpenClawCLI”) from an external site; if followed, the workflow fetched and executed a Base64-encoded command that dropped a Mach-O universal binary (Intel and Apple Silicon). Trend Micro reported 39 malicious skills uploaded across repositories and stated that more than 2,200 malicious skills were ultimately found on GitHub, with AMOS targeting credentials, browser data, crypto wallets, Telegram data, VPN profiles, Apple Keychain items, and common user folders—underscoring that AI-agent ecosystems are becoming a practical malware delivery and data-theft channel.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Zscaler ThreatLabz reported that a malicious OpenClaw skill named "DeepSeek-Claw" impersonated a DeepSeek integration and delivered two malware chains. On Windows it installed Remcos RAT via an MSI and DLL sideloading with a signed GoToMeeting executable, while manual install paths triggered the cross-platform GhostLoader stealer targeting developer credentials, wallets, SSH keys, and cloud tokens.
Acronis Threat Research Unit reported that ClawHub was hosting more than 575 malicious OpenClaw skills published by 13 developer accounts, with most attributed to the aliases hightower6eu and sakaen736jih. The report said the skills targeted Windows and macOS users with AMOS Stealer, trojans, and a cryptominer, using social engineering, hidden dependencies, password-protected archives, encoded commands, and prompt-injection-style abuse.
Manifold researcher Ax Sharma reported that 30 ClawHub skills published by the user "imaflytok" silently enrolled installed AI agents into a cryptocurrency-oriented swarm via onlyflies.buzz. The skills abused normal instruction files and skill functionality to make agents disclose metadata, store credentials locally, periodically check in, and in some cases generate Hedera wallets and submit private keys without user consent.
Silverfort reported a ClawHub vulnerability that could allow attackers to manipulate marketplace rankings and push a malicious skill to the number-one position. The disclosure introduced a new platform-level weakness that could amplify discovery and distribution of malicious skills beyond the previously documented ClawHavoc campaign tactics.
In March 2026, Breakglass Intelligence analyzed an active fake OpenClaw skill campaign delivering Atomic macOS Stealer and observed the operator replace the original dropper with a revised version that changed encryption, added anti-VM checks, and rotated C2 credentials. After researchers authenticated to the live C2 and mapped its protocol, the operator hardened the infrastructure within 29 minutes by removing console endpoints and blocking uploads while keeping token validation active.
PolySwarm publicly detailed the ClawHavoc campaign, including AMOS delivery on macOS, theft of OpenClaw bot configuration secrets, webhook-based exfiltration, and reverse shells. The report also described follow-on comment-based social engineering on popular Skills that redirected users to attacker infrastructure such as 91.92.242[.]30.
Staiker researchers identified a malicious ClawHub skill called "bob-p2p" that was promoted on Moltbook as a decentralized API marketplace. Once installed, it caused agents to store Solana wallet private keys in plaintext and buy worthless $BOB tokens while sending payments to attacker-controlled infrastructure.
Trend Micro reported a new Atomic macOS Stealer variant distributed through malicious OpenClaw skills uploaded to ClawHub, SkillsMP, and GitHub. The infection chain used benign-looking SKILL.md files to direct users to install a fake prerequisite and then execute a payload that could trigger a fake password prompt to capture the macOS system password.
By mid-February 2026, researchers said the campaign had grown to 824 identified malicious Skills, with more than 900 malicious Skills used overall as ClawHub exceeded 10,700 listed Skills. The operation targeted both Windows and macOS users with staged payload delivery, credential theft, reverse shells, and secret exfiltration.
PolySwarm reported that the ClawHavoc supply-chain poisoning campaign had already uploaded 341 malicious Skills to ClawHub by February 1, 2026. The skills used convincing documentation and fake setup prerequisites to trick OpenClaw users into executing malicious payloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourcezscaler.com
Open sourceacronis.com
Open sourceintel.breakglass.tech
Open sourceblog.polyswarm.io
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.