Sev0AI security incidents, tracked

All incidents / Supply chain and access

Hundreds of malicious OpenClaw skills spread info-stealer malware

OpenClaw users, disclosed Feb 2026. Supply chain and access Data exposed Medium

The ClawHub marketplace for the OpenClaw AI agent was flooded with malicious skills posing as crypto, productivity and updater tools. Researchers found 341 malicious skills in one audit, delivering macOS info-stealers, keyloggers and backdoors, some of which stole OpenClaw's own stored credentials.

Disclosed
Feb 2026
Organization
OpenClaw users
Vendor
Any model
Product
OpenClaw (ClawHub skills) (open source)
Kind of AI
Autonomous agent
AI's role
Poisoned supply chain
How it happened
Supply chain and access: Poisoned package
Harm
Data exposed
Data involved
Credentials
Reach
Limited
Severity
Medium
Model at fault
No
Status
Confirmed

Sources

  1. https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting
  2. https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html
  3. https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Hundreds of malicious OpenClaw skills spread info-stealer malware", https://sev0.fyi/incidents/2026-02-01-clawhavoc-malicious-openclaw-skills/