Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

ClawHavoc Poisoned OpenClaw’s ClawHub with 1,184 Malicious Skills, Enabling Data Theft and Backdoor Access

A recent campaign targeted OpenClaw’s marketplace, ClawHub, introducing 1,184 malicious Skills aimed at data theft and establishing backdoor access to compromised systems.

A recent campaign targeted OpenClaw’s marketplace, ClawHub, introducing 1,184 malicious Skills aimed at data theft and establishing backdoor access to compromised systems.

OpenClaw is an open-source AI agent platform allowing users to install Skills from ClawHub. In January 2026, threat actors registered as developers and uploaded trojanized Skills disguised as crypto trading bots, productivity tools, and social media utilities.

The campaign, named "ClawHavoc" by Koi Security, was first disclosed on February 1, 2026. Antiy CERT later identified the malware as belonging to the TrojanOpenClaw PolySkill family.

By February 5, researchers had linked 1,184 malicious packages to 12 publisher accounts, with one account responsible for 677 packages.

Attackers exploited ClawHub’s upload model, allowing any GitHub account older than one week to publish Skills. This led to 386 malicious Skills being uploaded from January 27–29, with many remaining live despite removal efforts.

OpenClaw is an open-source AI agent platform allowing users to install Skills from ClawHub.
Carter Hartwell · Thehackingpost

Each malicious Skill was packaged as a ZIP archive with hidden payloads. Antiy identified three primary behaviors:

ClickFix-style Downloaders: Prompt users to download external binaries, risking full system compromise. Reverse-Shell Droppers: Deploy payloads establishing reverse shell connections, enabling unauthorized access. Direct Data-Stealing Scripts: Execute scripts to collect and exfiltrate sensitive data, such as credentials and financial information.

In some instances, Skills instructed users to install components that redirected them to malware archives. On macOS, a variant of Atomic macOS Stealer was used to exfiltrate sensitive data.

Additional Skills harvested API keys or executed Python scripts to fetch malware and open reverse shells. Elevated privileges of AI agents made these plugins particularly dangerous.

Advertisement

The campaign highlighted vulnerabilities in AI marketplaces, including insufficient vetting and rapid development cycles. Security teams recommend reviewing installed Skills, removing suspicious ones, rotating credentials, and deploying endpoint protection to monitor agent-level activity.

ClawHavoc underscores the need for stronger marketplace governance to prevent AI supply-chain poisoning.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories