Wednesday, September 9, 2026

Abuse of OpenClaw AI Capabilities Enables Stealthy Malware Campaigns

Hundreds of malicious skills are distributed through OpenClaw’s marketplace, transforming the popular AI agent ecosystem into a new supply chain attack vector.

Threat actors are weaponizing the platform’s extensibility features to deliver droppers, backdoors, and infostealers disguised as legitimate automation tools.​

OpenClaw Skills Become Malware Distribution Channel

OpenClaw is a self-hosted AI agent that executes shell commands, file operations, and network requests on users’ systems.

The platform’s functionality is extended through skills third-party packages distributed via the ClawHub marketplace.

These skills contain SKILL.md files with metadata and instructions, along with executable scripts and resources.​

VirusTotal Code Insight has analyzed over 3,016 OpenClaw skills, and hundreds of them exhibit malicious characteristics.

VirusTotal Code Insight has already analyzed 314 skills (source: Virustotal)
VirusTotal Code Insight has already analyzed 314 skills (source: Virustotal)

While some contain poor security practices like hardcoded secrets and unsafe command execution, a significant portion are intentionally malicious, designed for data exfiltration, backdoor installation, and remote system control.​

malicious by multiple security vendors (source: Virustotal)
malicious by multiple security vendors (source: Virustotal)

Security researchers discovered that the ClawHub user “hightower6eu” was operating as a prolific malware publisher, with 314 skills identified as malicious.

The threat actor distributes skills masquerading as crypto analytics, financial tracking, and social media tools, all of which instruct users to download and execute external code during setup.​

Analysis of the “Yahoo Finance” skill revealed a sophisticated attack chain. Windows users are directed to download a password-protected ZIP file containing openclaw-agent.exe, which multiple vendors have flagged as a packed Trojan.

 stealer trojans and generic malware families (source: Virustotal)
 stealer trojans and generic malware families (source: Virustotal)

macOS users receive obfuscated Base64-encoded shell scripts that download and execute the Atomic Stealer (AMOS) malware, which harvests passwords, browser credentials, and cryptocurrency wallets.​

Detection and Mitigation

VirusTotal deployed Gemini 3 Flash-powered analysis to detect malicious OpenClaw skills by examining actual behavior rather than claimed functionality.

The platform now identifies skills that download external code, access sensitive data, or contain instructions that could compromise systems.​

Security experts recommend sandboxing OpenClaw executions, treating skill folders as trusted code boundaries, and scanning community skills before installation.

Marketplace operators should implement publish-time scanning to flag skills with remote execution capabilities or obfuscated scripts.​

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware

A multi-stage malware operation that combines fake Google CAPTCHA...

SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

Austin, Texas / USA, September 9th, 2026, CyberNewswire Ninety-five percent...

Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs

Iran-linked cyberespionage group Mirage Kitten is targeting software engineers...

Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root

Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to...

GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks

GoldFactory has expanded the evasion capabilities of its Gigabud...

Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems

Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker....

Related Articles

Recent News