Researchers found widespread supply-chain abuse in the OpenClaw ClawHub skill marketplace, identifying 341 malicious skills among 2,857 reviewed. Most of the malicious listings were tied to a coordinated campaign dubbed ClawHavoc, which used polished documentation and fake prerequisite steps to trick users into installing malware. On macOS, the skills directed OpenClaw to fetch and run obfuscated shell scripts and a fake OpenClawCLI component that ultimately delivered Atomic macOS Stealer (AMOS) as a universal Mach-O binary for both Intel and Apple Silicon systems; on Windows, the campaign used password-protected ZIP archives. The activity was also observed across multiple skill repositories and websites, showing that attackers are using AI agent workflows as a new malware delivery channel rather than relying only on direct user lures.
The AMOS payloads were reported to steal credentials, keychain contents, browser data, crypto-wallet information, Telegram sessions, Apple Notes, and files from common user directories before exfiltrating the data to attacker-controlled infrastructure. Researchers also found six additional malicious outlier skills using different techniques, including Polymarket-themed skills that embedded reverse-shell backdoors in otherwise normal code and another skill that sent a bot configuration file to a webhook. Koi Security said it reported the malicious skill list to ClawHub’s security team and released a defensive scanning skill, Clawdex, to help detect flagged skills before or after installation.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
On its publication date, TrendAI reported a campaign in which 39 malicious OpenClaw skills attempted to trick OpenClaw into installing a fake CLI component that fetched Atomic macOS Stealer. The report said the skills overlapped with Koi's larger ClawHavoc set and remained present in some repositories, including ClawHub's GitHub repository, at the time of writing.
Trend Micro published MDR analysis of an Atomic macOS Stealer campaign targeting macOS users through cracked applications. The reference provides only the publication date as an anchor for when this analysis occurred.
Koi launched Clawdex, a defensive skill intended to check ClawHub skills against a malicious-skills database before installation and to scan already installed skills retroactively. The tool was presented as a mitigation following the marketplace findings.
After identifying the malicious skills, Koi provided ClawHub's security team with the findings and the full list of flagged skills for removal. This was the direct disclosure step to the affected marketplace operator.
Koi analyzed the macOS infection chain used by ClawHavoc skills and assessed the downloaded universal Mach-O payload as Atomic macOS Stealer. The report described social-engineering instructions, staged shell execution from attacker infrastructure, and AMOS capabilities including theft of credentials, browser data, crypto wallets, Telegram sessions, files, and SSH material.
Koi Security audited the OpenClaw ClawHub skill marketplace and identified 341 malicious skills out of 2,857 total. Of these, 335 were assessed as part of a coordinated supply-chain campaign dubbed ClawHavoc, while six used separate techniques including reverse-shell and exfiltration behavior.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcetrendmicro.com
Open sourcekoi.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.