Rogue Agent Watch › Records › clawhavoc-clawhub-malicious-skills
ClawHavoc: large-scale poisoning of the OpenClaw ClawHub skill marketplace with credential-stealing skills
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Incidental — AI played a minor or supporting role (e.g. a productivity aid); sources indicate it did not provide novel capability.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
Koi Security disclosed on 2026-02-01 a campaign it named ClawHavoc, in which malicious "skills" were uploaded at scale to ClawHub, the skill marketplace for the OpenClaw AI agent. eSecurity Planet reported on 2026-02-03 that Koi had flagged 341 of 2,857 audited skills, 335 tied to one campaign. Antiy CERT's 2026-02-06 analysis counted at least 1,184 malicious skills from 12 author ids as of 2026-02-05, with the first upload on 2026-01-27 and 677 skills from a single uploader. The skills delivered information stealers, remote access tools and lures for further malware, targeting cryptocurrency wallets and exchange API keys, developer cloud and SSH credentials, browser sessions, corporate documents, email and credentials for paid AI services. Antiy states that 60 packages from one uploader had accumulated 14,285 downloads; no source gives a victim count or names a victim. Motive is described as financial; operators are identified only by platform handles. The AI agent platform is the attack surface rather than the attacker.
Impact as stated
At least 1,184 malicious skills on ClawHub as of 2026-02-05 per Antiy CERT (341 flagged in Koi Security's audit per eSecurity Planet); 14,285 downloads of 60 packages from one uploader; credential and wallet theft capability on affected systems. No confirmed victim count.
Facts as stated by sources
- Actor
- Unknown (operators identified only by ClawHub handles; financially motivated per Antiy CERT) (Cybercriminal)
- Category
- Infrastructure abuse / supply chain
- Models named
- not named by sources
- Model families
- Other / unspecified
- Agentic autonomy level
- Not applicable
- Guardrail bypass
- Legitimate tool abuse
- Attack lifecycle phases
- Resource development, Initial access, Execution, Credential access, Exfiltration
- Target sectors
- Technology
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Mitigations as stated
- Antiy CERT advises users to audit recent skill installs, remove malicious skills, rotate credentials, deploy endpoint security and avoid connecting sensitive platforms to agent tools; and advises platform operators to add automated static, semantic and sandbox review plus manual review and user-report handling.
- Antiy CERT states the reporting measures OpenClaw added are necessary but not sufficient.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- Amazon Q Developer VS Code extension compromise (data-wiping prompt injection)
- Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools
Sources (2)
- ClawHavoc: Analysis of Large-Scale Poisoning Campaign Targeting the OpenClaw Skill Market for AI Agents
Antiy CERT · Vendor report · · archived copy - Hundreds of Malicious Skills Found in OpenClaw's ClawHub
eSecurity Planet · News · · no archive recorded
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "clawhavoc-clawhub-malicious-skills". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/clawhavoc-clawhub-malicious-skills.json — CC BY-SA 4.0.