More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
OpenClaw lets users install “skills” from ClawHub, markdown-driven packages that can read, write or execute anything on a host. Soon after launch, researchers spotted waves of malicious skills. In February 2026, ClawHub added VirusTotal and ClawScan to block known threats, but an April–May review still found five active malicious skills. Two delivered macOS infostealers that phone home to C2 servers. One padded its files to dodge scanners. The last two used the agent itself for financial schemes: one injected affiliate links at runtime and another frontranned trades automatically.
Early ClawHub campaigns relied on Base64-encoded curl-pipe-bash droppers, platform-specific redirects (glot.io or rentry.co for macOS, password-protected Windows executables), cron-job auto-updaters and alternative C2 via Telegram Bot API. One publisher even flooded its entire skill catalog with identical payloads to boost installs. Bitdefender flagged 17 percent of early skills as malicious, Koi Security reported 341 bad packages, and Trend Micro traced Atomic macOS Stealer (AMOS).
A recent case targeted TradingView users. On May 17, an account published two macOS trading assistants carrying the same prerequisite block pointing agents to rentry[.]co/openclaw-code. That lure delivered a Base64 payload that fetched “cluw,” a new macOS infostealer."cluw" connects to 2.26.75[.]16, not the older 91.92.242[.]30 AMOS server. ClawHub’s automated audit still marked one skill “Pass” and the other unrated. In another example, the “omnicogg” skill padded its package—SHA256 b30eaed1f7478c28f4ec50d07ed5ef014ffbc4b2bc5a38d689ba9f7abb5e19c2—to slip past both VirusTotal and ClawScan.
After being notified, ClawHub removed the five skills and banned the offending accounts. They’ve since teamed up with NVIDIA for code-behavior documentation and to run NVIDIA’s analysis tools on every new skill. Users can also layer in protections like Koi Agentic Endpoint Security, Prisma Browser and Cortex XDR to block similar threats.
Questions about this article
No questions yet.