A major security warning has hit the OpenClaw AI ecosystem. Blockchain security firm SlowMist found a large supply chain attack inside ClawHub. It is a platformA major security warning has hit the OpenClaw AI ecosystem. Blockchain security firm SlowMist found a large supply chain attack inside ClawHub. It is a platform

SlowMist Finds 341 Malicious Skills in OpenClaw Plugin Hub

2026/02/09 14:33
Okuma süresi: 3 dk

A major security warning has hit the OpenClaw AI ecosystem. Blockchain security firm SlowMist found a large supply chain attack inside ClawHub. It is a platform’s plugin marketplace. The issue surfaced after Koi Security scanned 2,857 skills and flagged 341 of them as malicious.

That means around 12% of the scanned plugins carried harmful code. The discovery raised concerns because OpenClaw has grown fast in recent months. Its open-source agent tools attracted many developers. It is also made the platform a bigger target for attackers.

Weak Reviews Let Malicious Skills Slip In

The attack worked because of weak review checks in the plugin store. Hackers uploaded skills that looked normal on the surface. However, the code inside them carried hidden instructions. SlowMist said many of these skills used a two-stage attack. First, the plugin contained obfuscated commands. These often appeared as normal setup or dependency steps. But the commands secretly decoded hidden scripts.

Then, the second stage downloaded the real malicious payload. The code pulled data from fixed domains or IP addresses. After that, it executed malware on the victim’s system. One example involved a skill called “X (Twitter) Trends.” It looked harmless and useful. However, it hid a Base64-encoded backdoor. The code could steal passwords, collect files and send them to a remote server.

Hundreds of Malicious Plugins Found

The scale of the attack surprised many analysts. Out of 2,857 scanned skills, 341 showed malicious behavior. Koi Security linked most of them to one large campaign. SlowMist also analyzed more than 400 indicators of compromise. The data showed organized batch uploads. Many plugins used the same domains and infrastructure.

The risks were serious for users running these skills. Some plugins requested shell access or file permissions. That gave the malware a chance to steal credentials, documents, and API keys. Some fake skills even mimicked crypto tools, YouTube utilities or automation helpers. These familiar names made them easier to install without suspicion.

Security Firms Urge Caution

Security researchers have already started cleanup efforts. SlowMist reported hundreds of suspicious items during early scans. Meanwhile, Koi Security released a free scanner for OpenClaw skills. Experts now warn users to avoid blindly running plugin commands. Many attacks started from simple setup steps inside skill files. Users should also avoid skills that ask for passwords or broad system access.

Developers are also urged to test plugins in isolated environments. Independent scans and official sources should be the first line of defense. This incident shows the risks inside fast growing AI ecosystems. Plugin marketplaces often move quickly, but security checks may lag behind. As AI agents gain more power, these platforms will need stronger review systems. Until then, users may need to treat every plugin like a potential threat.

The post SlowMist Finds 341 Malicious Skills in OpenClaw Plugin Hub appeared first on Coinfomania.

Piyasa Fırsatı
OpenClaw Logosu
OpenClaw Fiyatı(OPENCLAW)
$0.0003501
$0.0003501$0.0003501
+15.50%
USD
OpenClaw (OPENCLAW) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

What Does Market Cap Really Mean in Crypto — and Why Australians Care

What Does Market Cap Really Mean in Crypto — and Why Australians Care

Introduction: What Does Market Cap Mean in Cryptocurrency Ridgewell Tradebit is an automated cryptocurrency trading platform that helps users better understand
Paylaş
Techbullion2026/02/09 23:34
The Manchester City Donnarumma Doubters Have Missed Something Huge

The Manchester City Donnarumma Doubters Have Missed Something Huge

The post The Manchester City Donnarumma Doubters Have Missed Something Huge appeared on BitcoinEthereumNews.com. MANCHESTER, ENGLAND – SEPTEMBER 14: Gianluigi Donnarumma of Manchester City celebrates the second City goal during the Premier League match between Manchester City and Manchester United at Etihad Stadium on September 14, 2025 in Manchester, England. (Photo by Visionhaus/Getty Images) Visionhaus/Getty Images For a goalkeeper who’d played an influential role in the club’s first-ever Champions League triumph, it was strange to see Gianluigi Donnarumma so easily discarded. Soccer is a brutal game, but the sudden, drastic demotion of the Italian from Paris Saint-Germain’s lineup for the UEFA Super Cup clash against Tottenham Hotspur before he was sold to Manchester City was shockingly brutal. Coach Luis Enrique isn’t a man who minces his words, so he was blunt when asked about the decision on social media. “I am supported by my club and we are trying to find the best solution,” he told a news conference. “It is a difficult decision. I only have praise for Donnarumma. He is one of the very best goalkeepers out there and an even better man. “But we were looking for a different profile. It’s very difficult to take these types of decisions.” The last line has really stuck, especially since it became clear that Manchester City was Donnarumma’s next destination. Pep Guardiola, under whom the Italian will be playing this season, is known for brutally axing goalkeepers he didn’t feel fit his profile. The most notorious was Joe Hart, who was jettisoned many years ago for very similar reasons to Enrique. So how can it be that the Catalan coach is turning once again to a so-called old-school keeper? Well, the truth, as so often the case, is not quite that simple. As Italian soccer expert James Horncastle pointed out in The Athletic, Enrique’s focus on needing a “different profile” is overblown. Lucas Chevalier,…
Paylaş
BitcoinEthereumNews2025/09/18 07:38
MicroStrategy Bought Another 1.142 BTC: Total 714K BTC

MicroStrategy Bought Another 1.142 BTC: Total 714K BTC

The post MicroStrategy Bought Another 1.142 BTC: Total 714K BTC appeared on BitcoinEthereumNews.com. MicroStrategy Continues BTC Purchases MicroStrategy, the world
Paylaş
BitcoinEthereumNews2026/02/09 23:06