A security audit of 2,857 ClawHub skills revealed 341 malicious skills across multiple campaigns, according to new findings from Koi Security, exposing users to new supply chain risks.
See also: Critical Chrome Vulnerability – Use After Free: Fix Immediately!

ClawHub is a marketplace designed to make it easier for OpenClaw users to find and install third-party skills. It is an extension of the OpenClaw project, a self-hosted artificial intelligence (AI) assistant formerly known as Clawdbot and Moltbot.
The analysis, conducted by Koi with the help of an OpenClaw bot named Alex, found that 335 skills use fake prerequisites to install a data stealer for Apple's macOS, called Atomic Stealer (AMOS). This set has been codenamed ClawHavoc.
This step includes instructions for Windows and macOS systems: On Windows, users are asked to download a file named “openclaw-agent.zip” from a GitHub repository. On macOS, the documentation tells them to copy an installation script hosted on glot[.]io and paste it into the Terminal. The targeting of macOS is no coincidence, as there have been reports of people buying Mac Minis to run the AI assistant 24×7.
Inside the password-protected file is a trojan with keylogging functionality to record API keys, credentials, and other sensitive data on the computer, including those already accessed by the bot. On the other hand, the glot[.]io script contains disguised shell commands to retrieve next-stage payloads from an attacker-controlled infrastructure.
See also: APT28 hackers exploit zero-day vulnerability in Microsoft Office

This, in turn, involves contacting another IP address (“91.92.242[.]30”) to retrieve another shell script, which is configured to contact the same server to obtain a universal Mach-O that exhibits features compatible with Atomic Stealer, a commercial stealer available for $500-1000/month that can harvest data from macOS hosts.
According to Koi, malicious skills pretend to be:
- – ClawHub typosquats (eg, clawhub, clawhub1, clawhubb, clawhubcli, clawwhub, cllawhub)
- – Cryptocurrency tools like Solana wallets and wallet trackers – Polymarket bots (e.g., polymarket-trader, polymarket-pro, polytrading)
- – YouTube tools (e.g., youtube-summarize, youtube-thumbnail-grabber, youtube-video-downloader)
- – Automatic updaters (e.g., auto-updater-agent, update, updater)
- – Financial and social media tools (e.g., yahoo-finance-pro, x-trends-tracker)
- – Google Workspace tools that claim to have integrations with Gmail, Calendar, Sheets, and Drive
- – Ethereum fuel trackers
- – Finding lost Bitcoins
Additionally, the cybersecurity firm reported that it detected skills that hide reverse shell backdoors within operational code (e.g., better-polymarket and polymarket-all-in-one), or export bot credentials located in “~/.clawdbot/.env” to a webhook[.]site (e.g., rankaj).
See also: HoneyMyte hackers upgrade CoolClient malware and steal data

The development coincides with a report from OpenSourceMalware, which also highlights the same ClawHavoc campaign targeting OpenClaw users.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
