# Malicious OpenClaw Skills Expose Critical Gaps in AI Agent Supply Chain Security


Five malicious packages discovered on ClawHub marketplace highlight the emerging threat landscape targeting AI supply chains, as threat actors exploit weak vetting processes to distribute infostealers, detection evasion tools, and novel agentic attack techniques.


## The Threat


Palo Alto Networks' Unit 42 security research team has identified five malicious skills distributed through ClawHub, the official marketplace for the OpenClaw AI agent framework. These packages, which appeared legitimate to end users, were designed to steal credentials, bypass security detection systems, and execute unauthorized actions on behalf of compromised systems.


The five malicious skills represent three distinct threat categories:


| Threat Category | Count | Capability | Risk Level |

|---|---|---|---|

| Infostealers | 2 | Credential theft, C2 communication | CRITICAL |

| Detection Evasion | 1 | Scanner bypass (ClawScan, VirusTotal) | HIGH |

| Agentic Threats | 2 | Unauthorized agent manipulation | HIGH |


According to Unit 42 researchers, these skills were removed from ClawHub on June 23, 2026, after discovery. However, the incident raises serious questions about the security posture of AI agent marketplaces and the supply chain risks inherent in rapidly expanding AI ecosystems.


## Background and Context


OpenClaw, an open-source AI agent framework that launched in November 2025, has experienced meteoric adoption among developers and enterprises seeking to deploy autonomous AI systems. The platform's extensibility through "skills"—modular packages that grant agents access to local files, credentials, APIs, and system resources—has been central to its popularity. However, this same extensibility creates a significant attack surface.


ClawHub, OpenClaw's dedicated skills marketplace, functions similarly to traditional software package repositories like npm or PyPI, but with notably less stringent security vetting. The marketplace allows developers to publish skills that integrate directly with agent ecosystems, often with elevated permissions.


The discovery of malicious skills on ClawHub represents a watershed moment for AI security: threat actors have identified and are actively exploiting the gap between rapid platform growth and security infrastructure maturity.


### Why This Timing Matters


OpenClaw's explosive adoption has occurred faster than security controls could scale. Unlike mature ecosystems that evolved security practices over years, ClawHub's vetting processes were not designed to catch sophisticated social engineering or obfuscation techniques. The infostealers targeting macOS, for instance, leveraged standard packaging deception—appearing as legitimate utilities while establishing command-and-control communications in the background.


## Technical Details


### Infostealer Skills (2 Identified)


Two malicious skills were configured as credential-harvesting tools targeting macOS environments. These packages:


  • Established persistence by registering C2 (command-and-control) infrastructure callbacks
  • Harvested credentials from local credential stores, SSH keys, and API configuration files
  • Exfiltrated sensitive data including system information, environment variables, and file metadata

  • The infostealer distribution suggests attackers specifically targeted the developer community, where macOS adoption is highest and the likelihood of accessing high-value credentials (API keys, cloud service tokens, source repository credentials) is greatest.


    ### Detection Evasion Skill (1 Identified)


    One malicious skill employed a novel evasion technique: inflating file size beyond typical scanner thresholds. This approach:


  • Bypassed ClawScan (ClawHub's native detection system) by exploiting file-size-based filtering
  • Defeated VirusTotal detection through similar obfuscation
  • Exploited scanner resource limitations, as many antivirus and malware detection platforms skip analysis of oversized files to preserve computational resources

  • This technique is not novel in traditional malware distribution, but its application to AI agent marketplaces demonstrates attackers are adapting proven evasion tactics to new platforms.


    ### Agentic Threat Skills (2 Identified)


    The most concerning discoveries were two skills representing previously undocumented attack patterns:


    Agentic Affiliate Injection: These skills allowed attackers to inject hidden instructions into agent decision-making workflows, causing systems to execute unauthorized transactions or services on behalf of legitimate users. In financial contexts, this could redirect payments or initiate transfers without explicit user approval.


    Agentic Front-Running: Similar to financial front-running attacks, these skills enabled attackers to observe pending agent actions and inject their own operations first, potentially allowing theft of value or manipulation of outcomes before legitimate transactions complete.


    Both techniques exploit the unique characteristics of autonomous agents—their ability to execute actions independently and without real-time human verification—creating a new attack surface not present in traditional software.


    ## Implications for Organizations


    ### Immediate Risks


    Organizations deploying OpenClaw agents face several concrete threats:


  • Credential compromise: Malicious skills can harvest API keys, cloud credentials, and authentication tokens stored on systems running OpenClaw agents
  • Lateral movement: Compromised agent systems can serve as beachheads for broader network intrusions
  • Supply chain cascade: A single developer's compromised system could distribute malicious skills widely through legitimate-appearing updates
  • Financial manipulation: Agentic attack techniques could enable unauthorized transactions in financial or commerce workflows

  • ### Broader Ecosystem Concerns


    The ClawHub incident exposes a fundamental challenge in AI supply chain security: platform operators cannot adequately vet code for novel attack patterns when the attack patterns themselves are still being discovered.


    Traditional software security evolved control frameworks over decades. AI agent platforms are attempting to compress that timeline, with inevitably mixed results. The gap between platform maturity and threat sophistication creates a persistent vulnerability window.


    ## Recommendations


    ### For Organizations Using OpenClaw


    1. Implement runtime isolation — run OpenClaw agents in sandboxed environments with minimal credential access

    2. Establish skill vetting procedures — require internal security review before deploying any new skills, even from official marketplaces

    3. Monitor skill behavior — implement logging and behavioral analysis to detect anomalous agent activities

    4. Limit agent permissions — restrict API access, file system permissions, and credential availability to only what the agent legitimately requires

    5. Maintain an audit trail — log all agent actions and data access for forensic analysis


    ### For ClawHub and Platform Operators


    1. Strengthen vetting processes — implement dynamic code analysis, sandboxed testing, and behavioral detection before marketplace publication

    2. Require cryptographic signing — mandate developer verification and code signing to enable user accountability

    3. Implement ongoing monitoring — use behavioral analytics to detect malicious activity post-publication

    4. Establish rapid response procedures — create expedited takedown and rollback mechanisms for compromised skills

    5. Provide transparency — publish security incident reports and share threat intelligence with the broader community


    ### For the Security Industry


    1. Document agentic attack patterns — formalize the emerging threat landscape around agent manipulation and financial abuse

    2. Develop detection baselines — create signatures and behavioral indicators for agentic threats

    3. Share threat intelligence — establish industry channels for reporting and coordinating on AI supply chain incidents


    ---


    ## HackWire Analysis


    The ClawHub incident represents a critical inflection point for AI security. While the immediate threat is contained—five skills affecting what appears to be a limited user base—the systemic risk is far more significant.


    The core issue: AI agent platforms are inherently more dangerous than traditional software because agents execute autonomously with access to credentials and systems. A malicious npm package might sit dormant in a code repository; a malicious OpenClaw skill actively executes in production, making autonomous decisions with real-world consequences.


    What's particularly concerning is the novelty of the attack patterns themselves. The infostealer and detection evasion skills are adaptations of known techniques, but agentic affiliate injection and front-running represent entirely new attack categories with no established defenses. This suggests we're in the early stages of discovering the full threat landscape around autonomous agents—and what we've found so far may be just the beginning.


    The broader pattern is troubling: major AI platforms are shipping security infrastructure that assumes threats it cannot yet imagine. ClawHub's vetting process wasn't designed to catch agentic attacks because those attacks didn't have names or documented patterns when the platform launched. By the time researchers formalized them, malicious actors had already weaponized them.


    Organizations need to treat OpenClaw and similar platforms not as vetted software repositories (the npm/PyPI model) but as untrusted code execution environments where every third-party skill is suspicious until proven otherwise. That means runtime isolation, behavioral monitoring, and permission minimization—not mere marketplace reviews.


    The industry should also accelerate formalization of agentic threat models. Security frameworks exist for traditional software, containerized applications, and cloud infrastructure. We need equivalently rigorous frameworks for autonomous agents before adoption accelerates further.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)