Hundreds of malicious OpenClaw skills spread info-stealer malware
The ClawHub marketplace for the OpenClaw AI agent was flooded with malicious skills posing as crypto, productivity and updater tools. Researchers found 341 malicious skills in one audit, delivering macOS info-stealers, keyloggers and backdoors, some of which stole OpenClaw's own stored credentials.
- Disclosed
- Feb 2026
- Organization
- OpenClaw users
- Vendor
- Any model
- Product
- OpenClaw (ClawHub skills) (open source)
- Kind of AI
- Autonomous agent
- AI's role
- Poisoned supply chain
- How it happened
- Supply chain and access: Poisoned package
- Harm
- Data exposed
- Data involved
- Credentials
- Reach
- Limited
- Severity
- Medium
- Model at fault
- No
- Status
- Confirmed
Sources
- https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting
- https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html
- https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap