Hundreds of malicious OpenClaw skills spread info-stealer malware
What happened
The ClawHub marketplace for the OpenClaw AI agent was flooded with malicious skills posing as crypto, productivity and updater tools. Researchers found 341 malicious skills in one audit, delivering macOS info-stealers, keyloggers and backdoors, some of which stole OpenClaw's own stored credentials.
ClawHub is the marketplace where OpenClaw users find and install skills, add-ons that give their AI agent new abilities. Koi Security audited all 2,857 skills listed at the time and found 341 malicious ones, 335 of them part of one campaign it named ClawHavoc, uploaded in waves from late January. They posed as crypto wallet trackers, Polymarket trading bots, YouTube tools, auto-updaters, finance and Google Workspace integrations, and look-alikes of ClawHub's own name, each with professional documentation. A "prerequisites" section told users to install a helper tool first, which pulled down Atomic Stealer, a commodity macOS info-stealer that harvests passwords, browser data and crypto wallets, and in some cases OpenClaw's own stored credentials and configuration. Later counts by researchers put the total number of malicious skills at around 900 to more than 1,100 as the registry grew.
How it happened
Supply chain and access: Poisoned package. A malicious or tampered AI package, extension, plugin or MCP server was published and installed by users.
The software involved works with many AI models, so no single model maker was involved. The product was OpenClaw (ClawHub skills), which is open source, a type of AI agent.
Impact
Data was exposed. Data involved: credentials. The impact was limited to a small number of people or a single system.
Severity is rated Medium, calculated from how far the incident reached and how sensitive the data was.
Was the AI at fault?
No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.
Status and timeline
Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.
It became public on 2 Feb 2026.
Following the reports, OpenClaw's creator added a way for users to report malicious skills. The number of infected users has not been established.
Sources
- https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting
- https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html
- https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap