Malicious skills on the ClawHub marketplace hijack OpenClaw agents
- occurred
- 2026-02-04
- reported
- 2026-02-04
- location
- online
- domain
- software engineering
- agent system
- OpenClaw agents and the ClawHub skill marketplace
- reporter
- VAIDDB editorial
- origin
- editorial
== SUMMARY ==
Attackers mass-uploaded cloned "skills" carrying macOS and Windows infostealers to the ClawHub marketplace, including agentic fraud skills that used the victim's own agent to inject affiliate links and run crypto pump-and-dumps.
== DESCRIPTION ==
OpenClaw is an open-source personal AI agent whose capabilities are extended by community "skills" from the ClawHub marketplace. On 4 February 2026 a GitHub issue reported an active supply-chain attack in which an account was mass-uploading clones of popular skills with embedded malware payloads.
Palo Alto Networks Unit 42 subsequently found five persistent, evasive malicious skills on ClawHub between February and May 2026: two macOS infostealers, one file-size-padded skill that evaded both VirusTotal and ClawScan, and two agentic financial-fraud skills that used the agent itself to inject affiliate links or run pump-and-dump schemes. Skills run with the agent's own local privileges.
== ROOT CAUSE ==
The marketplace treated third-party, markdown-driven skill packages as trusted, granting them the agent's full local privileges while automated scanning could be bypassed.
== MITIGATION ==
OpenClaw removed the malicious skills, banned the accounts and integrated VirusTotal and ClawScan screening; users were advised to audit installed skills.
== REFERENCES ==
- news More malicious OpenClaw skills threaten AI supply chain — Dark Reading, 2026-06-23
- official report OpenClaw's skill marketplace and the emerging AI supply chain threat — Palo Alto Networks Unit 42, 2026-06-23
== INVESTIGATION ==
Takedown of reported malicious skills and account bans, followed by integration of automated malware screening; Unit 42 confirmed the removals.
== VAID LEVEL 3: SERIOUS INCIDENT ==
Near-accident: safety margins largely exhausted.
- Multiple control layers failed; only one barrier prevented harm.
- Unauthorised irreversible action attempted but blocked or reverted.
- Confidential data left the trust boundary in small volume.