Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› ClawHub Malicious Skills 2026: How Hundreds of Fake…
Breach analysis Incident: 1 Feb 2026

ClawHub Malicious Skills 2026: How Hundreds of Fake OpenClaw Agent Skills Delivered Credential Stealers

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
Category: AI agents NHI
Attack route: Supply chain Social engineering Identities: AI agent API key
On this page

From late January 2026, attackers uploaded hundreds of malicious "skills" to ClawHub, the public marketplace for OpenClaw, the open-source personal AI agent. The skills posed as crypto wallet trackers, trading bots, YouTube tools and other utilities. Each carried a "Prerequisites" section telling the user, or the agent, to download a password-protected archive or paste a command that fetched an information stealer, which researchers identified as Atomic macOS Stealer (AMOS) and Windows stealers. OpenSourceMalware raised the alarm on 1 February 2026 and said one publisher's skills alone had almost 7,000 downloads. Koi Security then audited all 2,857 skills on ClawHub and found 341 malicious, 335 of them in a campaign it named ClawHavoc. The stealers targeted exchange API keys, wallet keys, SSH keys, browser passwords and agent credentials. OpenClaw added skill reporting and, on 7 February, VirusTotal scanning. No confirmed victim count has been published.

Key takeaways

  • Koi Security found 341 malicious skills among the 2,857 on ClawHub, 335 of them in one campaign, ClawHavoc, that used fake prerequisites to install credential stealers, The Hacker News reported on 2 February 2026.
  • OpenSourceMalware first reported the campaign on 1 February 2026 and said one publisher, whose account uploaded most of the second wave, accounted for almost 7,000 downloads.
  • The stealers went after exchange API keys, wallet private keys, SSH keys, browser passwords and the credentials OpenClaw itself holds; one skill read the agent's .env file and sent it to a webhook.
  • OpenClaw added community reporting and then VirusTotal scanning of every skill, while warning that scanning "is not a silver bullet". No confirmed victims or losses have been published.
  • The identity lesson: a skill runs with the agent's access to the user's tools, files and keys, so installing one is a grant of identity, not just of code.

At a glance

OrganisationsOpenClaw and its ClawHub skill marketplace; users who installed skills on macOS and Windows, many running OpenClaw for crypto trading and automation
WhenMalicious skills uploaded from 27 January 2026; first reported by OpenSourceMalware on 1 February 2026; Koi Security's ClawHavoc findings reported 2 February 2026; VirusTotal scanning added 7 February 2026
AttackerUnknown. Researchers say the ClawHavoc skills shared one command-and-control server; most second-wave skills came from one ClawHub account
Entry pointMalicious skills published to ClawHub, which only required a GitHub account at least a week old, with fake installation prerequisites
Identities abusedTargeted: the OpenClaw agent's access and stored credentials, exchange API keys, wallet keys, SSH keys, cloud credentials and browser passwords on the user's machine
ImpactHundreds of credential-stealing skills live on the official marketplace with thousands of downloads; no confirmed victims or losses published
CategoryAgentic AI and AI agents, NHI. Incident class: AI-agent incident or attempt (malicious agent skills distributed at scale; no confirmed victims)

What happened

OpenClaw, earlier known as Clawdbot and Moltbot, is an open-source AI agent that people run on their own computers to manage email, files, trading and other tasks. Its capabilities are extended with skills, packages of instructions and code shared through ClawHub. OpenClaw's own description is plain: "Skills are code that runs in your agent's context, with access to your tools and your data."

On 1 February 2026, OpenSourceMalware reported that malicious skills had been published in two waves, the first between 27 and 29 January and a much larger one from 31 January. They posed as cryptocurrency and automation tools. On macOS, the skill told the user to run a base64-encoded shell command that fetched a script from the attacker's server; on Windows, to download and run a password-protected archive. OpenSourceMalware said one account published most of the second wave and that "This user alone accounts for almost 7000 downloads". At the time it reported that the maintainers did not plan to remove the skills.

The next day, The Hacker News reported Koi Security's audit. Researcher Oren Yomtov, working with his own OpenClaw assistant, scanned all 2,857 skills and found 341 malicious, 335 of which belonged to the ClawHavoc campaign. "You install what looks like a legitimate skill – maybe solana-wallet-tracker or youtube-summarize-pro," Yomtov said. "But there's a 'Prerequisites' section that says you need to install something first." The macOS payload matched Atomic macOS Stealer, a commodity tool that takes Keychain passwords, browser data, crypto wallets and SSH keys. Paul McCarty of OpenSourceMalware said the skills aimed at exchange API keys, wallet private keys, SSH credentials and browser passwords, and that "All these skills share the same command-and-control infrastructure". Other skills hid reverse shells or, in one case, sent the agent's own credentials file to a webhook.

Sources differ on who ran the payload. OpenSourceMalware describes social engineering of the human user. Palo Alto Networks' Unit 42 later described the early dropper as "a fake prerequisite block that instructed the agent to decode and execute a Base64-encoded remote payload", and concluded that for skills, "installation results in complete control over the agent's identity." OpenClaw creator Peter Steinberger added a reporting feature, and on 7 February OpenClaw announced that "All skills published to ClawHub are now scanned using VirusTotal's threat intelligence", while warning that "this is not a silver bullet." Unit 42 found five further malicious skills that evaded detection between February and May 2026.

Timeline

DateEvent
27 January 2026The first malicious skills are published to ClawHub, according to OpenSourceMalware.
31 January 2026A second, much larger wave of malicious skills begins.
1 February 2026OpenSourceMalware publishes its report on malicious ClawHub skills.
2 February 2026The Hacker News reports Koi Security's audit: 341 malicious skills, 335 in the ClawHavoc campaign.
4 February 2026SC Media reports the findings and Koi's Clawdex scanning tool.
7 February 2026OpenClaw announces VirusTotal scanning of all ClawHub skills.
23 June 2026Unit 42 reports further malicious skills that passed detection between February and May.

How it happened: the identity attack path

  1. Open marketplace. ClawHub let anyone with a GitHub account at least a week old publish skills, with no review.
  2. Trusted-looking skills. Attackers published hundreds of professional-looking skills for popular tasks, including typosquats of ClawHub's own tools.
  3. Fake prerequisites. Each skill said something had to be installed first, and gave a command or archive that fetched a stealer, aimed at the user or, according to Unit 42, at the agent itself.
  4. Agent and user credentials exposed. The stealer ran with the user's privileges on the machine where the agent held its API keys and the user kept wallets, SSH keys and browser passwords.
  5. Detection catches up. Researchers reported the skills, OpenClaw added reporting and VirusTotal scanning, and later skills were built to evade those scanners.

Impact

  • Confirmed: 341 malicious skills among 2,857 on ClawHub at the time of Koi's audit, distributed through the platform's official marketplace.
  • Reported exposure: OpenSourceMalware said one publisher's skills accounted for almost 7,000 downloads. Downloads do not confirm infections.
  • Not reported: no confirmed victim count, stolen credential count or losses have been published.
  • Potential: theft of exchange API keys, wallet keys, SSH keys, browser passwords and the agent's own credentials for anyone who followed a skill's prerequisites.

What this means for NHI and AI agent security

ClawHub turned a familiar supply chain attack, the malicious package, into an attack on AI agents. The agent here is OpenClaw, run by individuals on their own machines, often with access to email, files, exchange accounts and crypto wallets. Nothing was changed in its safeguards. Users, and possibly the agents acting for them, simply followed a skill's instructions. Koi Security found the problem by having an agent audit the marketplace, and OpenSourceMalware reported it independently.

The lesson is that skills, plugins and MCP servers are identity grants. Installing one gives it the agent's reach, and the agent's reach is usually everything the user can do. Marketplaces need publisher verification and review, and organisations need to know which agents and skills their people run. See our Shadow AI Discovery Guide and AI Supply Chain and AI-BOM Guide.

Recommendations

  • Treat every agent skill as privileged code. Install skills only from verified publishers, read them before use and never run their "prerequisite" commands blindly. See our AI Supply Chain and AI-BOM Guide.
  • Discover agents and skills in use. Inventory personal AI agents such as OpenClaw on company devices and the skills installed on them. See our Shadow AI Discovery Guide.
  • Run agents with least privilege. Isolate agents in a separate account or sandbox, without access to wallets, SSH keys or the user's browser profile. See our Zero Trust for AI Agents Guide.
  • Give agents scoped, revocable credentials. Store agent API keys in a secrets manager rather than plain .env files, scope them tightly and rotate them after any suspicious skill install. See our API Key Management Guide.
  • Rotate everything after a malicious install. Revoke exchange API keys, move wallet funds, replace SSH keys and change browser-saved passwords on any affected machine. See the Leaked Credential Response Playbook.

Frequently asked questions

What were the malicious ClawHub skills?

They were add-ons for the OpenClaw AI agent, published to its ClawHub marketplace from late January 2026, that posed as crypto, trading and productivity tools. Their "Prerequisites" told users to run commands or archives that installed information stealers such as Atomic macOS Stealer.

What is ClawHavoc?

ClawHavoc is Koi Security's name for the campaign behind 335 of the 341 malicious skills it found when it audited all 2,857 skills on ClawHub. The skills shared the same command-and-control server and used fake prerequisites to deliver stealers.

Is OpenClaw safe to use after the ClawHub malware?

OpenClaw now scans every ClawHub skill with VirusTotal and lets users report skills, but its maintainers say scanning is not a silver bullet, and Unit 42 found malicious skills that evaded detection months later. Use skills from trusted publishers only, read them before installing and keep the agent away from wallets and sensitive keys.

Moltbook Database Exposure 2026 · TrapDoor Supply Chain Campaign 2026 · postmark-mcp Malicious MCP Server 2025 · AI Supply Chain and AI-BOM Guide · Shadow AI Discovery Guide

How NHI Mgmt Group can help

Personal AI agents and their skills are arriving on work machines faster than policies can follow. We help teams find them, decide what access they should have and treat skills and plugins as identity grants rather than harmless add-ons. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org