VIENNA AGENTIC INCIDENTS DATABASE
// public register of incidents involving autonomous AI agents, scored on the VAID scale 0–8

register / VAID-2026-0031

3
SERIOUS INCIDENT
Incident

Malicious skills on the ClawHub marketplace hijack OpenClaw agents

REF VAID-2026-0031 STATUS RESOLVED
occurred
2026-02-04
reported
2026-02-04
location
online
domain
software engineering
agent system
OpenClaw agents and the ClawHub skill marketplace
reporter
VAIDDB editorial
origin
editorial

== SUMMARY ==

Attackers mass-uploaded cloned "skills" carrying macOS and Windows infostealers to the ClawHub marketplace, including agentic fraud skills that used the victim's own agent to inject affiliate links and run crypto pump-and-dumps.

== DESCRIPTION ==

OpenClaw is an open-source personal AI agent whose capabilities are extended by community "skills" from the ClawHub marketplace. On 4 February 2026 a GitHub issue reported an active supply-chain attack in which an account was mass-uploading clones of popular skills with embedded malware payloads.

Palo Alto Networks Unit 42 subsequently found five persistent, evasive malicious skills on ClawHub between February and May 2026: two macOS infostealers, one file-size-padded skill that evaded both VirusTotal and ClawScan, and two agentic financial-fraud skills that used the agent itself to inject affiliate links or run pump-and-dump schemes. Skills run with the agent's own local privileges.

== ROOT CAUSE ==

The marketplace treated third-party, markdown-driven skill packages as trusted, granting them the agent's full local privileges while automated scanning could be bypassed.

== MITIGATION ==

OpenClaw removed the malicious skills, banned the accounts and integrated VirusTotal and ClawScan screening; users were advised to audit installed skills.

== REFERENCES ==

  1. news More malicious OpenClaw skills threaten AI supply chain — Dark Reading, 2026-06-23
  2. official report OpenClaw's skill marketplace and the emerging AI supply chain threat — Palo Alto Networks Unit 42, 2026-06-23

== INVESTIGATION ==

FINISHED OpenClaw / ClawHub opened 2026-02-04 · closed 2026-06-23

Takedown of reported malicious skills and account bans, followed by integration of automated malware screening; Unit 42 confirmed the removals.

report files: none yet

== VAID LEVEL 3: SERIOUS INCIDENT ==

Near-accident: safety margins largely exhausted.

  • Multiple control layers failed; only one barrier prevented harm.
  • Unauthorised irreversible action attempted but blocked or reverted.
  • Confidential data left the trust boundary in small volume.

> full scale definition