Cybersecurity researchers have revealed that they have identified a case of an infostealer malware infection , which successfully managed to extract a user's OpenClaw (formerly Clawdbot and Moltbot) configuration environment

“ This discovery marks a significant milestone in the evolution of infostealer behavior: the transition from stealing browser credentials to harvesting the ‘souls’ and identities of personal AI agents ,” Hudson Rock said .
Alon Gal, CTO of Hudson Rock, told The Hacker News that the malware was likely a variant of Vidar. Vidar is an infostealer malware that has been active since late 2018.
See also: Pastebin comments promote ClickFix JavaScript attack
The cybersecurity firm noted that the data theft was not facilitated by a custom OpenClaw module within the malware, but rather through a “generic file collection routine,” designed to look for specific file extensions and directory names that contain sensitive data.
OpenClaw: What files were collected by infostealer?
– openclaw.json, which contains details about the OpenClaw gateway token, along with the victim's deleted email address and workspace path.
– device.json, which contains cryptographic keys for secure pairing and signing functions within the OpenClaw ecosystem.
– soul.md, which contains details about the agent's basic operating principles, behavioral guidelines, and ethical boundaries.
Stealing the gateway authentication token can allow an attacker to remotely connect to the victim's local OpenClaw instance, if the port is exposed, or even impersonate the client in authentication requests to the AI gateway.
See also: LockBit 5.0 attacks Windows, Linux & ESXI systems

“While the malware may have been looking for typical ‘secrets,’ it accidentally ‘found gold’ by capturing the entire operating AI assistant user’s,” Hudson Rock added. “As AI agents, like OpenClaw, become more integrated into business workflows, infostealer developers will likely release custom modules designed to decrypt and analyze these files, much like they do today for Chrome or Telegram.
The revelation comes as security issues with OpenClaw prompted the platform's maintainers to announce a partnership with VirusTotal to scan for malicious skills uploaded to ClawHub and add the ability to check for potential misconfigurations.
Last week, the OpenSourceMalware analyzed an ongoing skills malware campaign on ClawHub, which uses a new technique to bypass VirusTotal scanning by hosting the malware on OpenClaw-like websites and using the skills only as bait (instead of embedding the payload directly into their SKILL.md files).
See also: Malicious Chrome extensions steal data, emails and browsing history
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“The shift from embedded payloads to external malware hosting shows that malicious actors are adapting to detection capabilities,” said security researcher Paul McCarty. “As AI skill registries grow, they are becoming increasingly attractive targets for supply chain attacks.”
