Malicious OpenClaw Skills Used to Trick Users into Manual Password Entry for AMOS Infection
The Atomic macOS Stealer (AMOS), a prominent data-theft malware, has modified its delivery approach to target victims. Previously distributed through cracked software downloads, it is now embedded within malicious OpenClaw skills—add-on packages that…
The Atomic macOS Stealer (AMOS), a prominent data-theft malware, has modified its delivery approach to target victims. Previously distributed through cracked software downloads, it is now embedded within malicious OpenClaw skills—add-on packages that enhance AI agent capabilities on platforms such as OpenClaw.
AMOS functions as a malware-as-a-service (MaaS) tool designed to extract sensitive information from Apple users. It collects a variety of data, including credentials, browser data, cryptocurrency wallet details, Telegram chats, VPN profiles, Apple keychain items, and files from folders like Desktop, Documents, and Downloads.
Trend Micro analysts identified a new AMOS variant within OpenClaw skills, tracking the campaign across multiple repositories. Threat actors uploaded 39 malicious skills to platforms like ClawHub, SkillsMP, and GitHub, with over 2,200 malicious skills found on GitHub alone.
This campaign signifies a transition from previous AMOS delivery methods, introducing a supply chain attack targeting AI agent workflows. The attack initiates with a SKILL.md file that appears harmless, instructing the AI agent to install a fraudulent prerequisite called "OpenClawCLI" from a malicious external website.
When models such as GPT-4o process the instruction, they may either install the tool silently or prompt the user to manually install the fake "driver." In contrast, more capable models like Claude Opus 4.5 detect the skill as suspicious and halt the process.
If a user or AI agent continues, a Base64-encoded command is executed, dropping a Mach-O universal binary compatible with both Intel-based and Apple Silicon Mac machines. Upon macOS rejecting the unsigned file, a fake password dialogue box prompts the user to enter their system password, granting the malware necessary access.
Upon password entry, AMOS immediately begins data collection. It harvests the machine's username and password, files from Desktop, Downloads, and Documents folders (including .pdf, .csv, .kdbx, and .docx formats), Apple keychain credentials, and Apple Notes. The malware targets 19 browsers for stored cookies, passwords, and credit card data, and can access over 150 cryptocurrency wallets.
The Atomic macOS Stealer (AMOS), a prominent data-theft malware, has modified its delivery approach to target victims.
All gathered data is compressed into a ZIP archive and uploaded to a command-and-control (C&C) server at socifiapp[.]com.
Users are advised to verify the source of any OpenClaw skill before execution, avoid entering system passwords into unfamiliar tools, test unvalidated skills in an isolated environment, and utilize containers to limit AI agent execution.
Type Indicator Description
URL hxxps://openclawcli[.]vercel[.]app/ Malicious skill delivery site
IP Address 91.92.242[.]30 Payload download server
URL hxxp://91.92.242[.]30/ece0f208u7uqhs6x Payload download URL
File Name il24xgriequcys45 Mach-O universal binary (AMOS payload)
C2 Server socifiapp[.]com Command-and-control exfiltration endpoint
Detection Name Trojan.MacOS.Amos AMOS malware detection name
Based on reporting by Cyber Security News.
