Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

OpenClaw’s Top Skill is a Malware that Stole SSH Keys and Opened Reverse Shells in 1,184 Packages

The ClawHub marketplace on the OpenClaw platform has recently been found to contain a significant number of malicious AI agent skills. This discovery highlights a severe vulnerability within the AI agent ecosystem.

The ClawHub marketplace on the OpenClaw platform has recently been found to contain a significant number of malicious AI agent skills. This discovery highlights a severe vulnerability within the AI agent ecosystem.

Security analysis has revealed that the most downloaded AI agent skill on ClawHub was functional malware. This skill was not a productivity tool but rather a malicious software designed to compromise systems.

OpenClaw is an open-source platform offering a public skill marketplace, ClawHub, where developers can publish plugins or "skills" to enhance an agent's functionality. It was discovered that 1,184 malicious skills were present, with a single threat actor accounting for 677 of these. This situation exposes a significant supply chain vulnerability within the platform.

The platform's policy allowed anyone with a GitHub account older than one week to publish skills, which attackers exploited by introducing malicious skills disguised as legitimate tools. These included crypto trading bots, YouTube summarizers, and wallet trackers, all supported by professional documentation.

Malicious instructions were embedded in the SKILL.md files, guiding users to execute harmful commands, such as:

The ClawHub marketplace on the OpenClaw platform has recently been found to contain a significant number of malicious AI agent skills.
Olivia Harper · Thehackingpost

On macOS, this command deployed Atomic Stealer (AMOS), an infostealer that targeted browser passwords, SSH keys, and other sensitive information. On other operating systems, the malware facilitated a reverse shell, giving attackers control over the affected machine.

Cisco's AI Defense team identified vulnerabilities in the top-ranked community skill, "What Would Elon Do?" This skill was manipulated to be highly ranked and exhibited 9 security vulnerabilities: 2 Critical, 5 High, and 2 Medium. It exfiltrated user data via a curl command to an attacker-controlled server, bypassing detection.

Previous Findings and Ongoing Measures

Prior audits by Koi Security and Snyk identified a significant number of malicious entries, with a coordinated campaign named ClawHavoc accounting for a substantial portion. These malicious skills shared a common command-and-control server.

OpenClaw has since partnered with Google’s VirusTotal for scanning all uploaded skills, categorizing them as benign, suspicious, or malicious, with ongoing daily re-scans to address potential mutations in skills.

Advertisement

This scenario is akin to npm supply chain attacks, with the distinction that malicious packages within AI agents have extensive system permissions and can autonomously execute commands. Traditional detection tools may not effectively identify these threats due to their embedded natural language instructions.

Organizations using OpenClaw in enterprise environments face increased risks, as actions executed by the AI agents may bypass standard monitoring and leave minimal traces.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories