The post OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks appeared first on Coinpedia Fintech News OpenClaw’s fast-growing pluginThe post OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks appeared first on Coinpedia Fintech News OpenClaw’s fast-growing plugin

OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks

2026/02/09 15:23
Okuma süresi: 3 dk
Makina Finance hack

The post OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks appeared first on Coinpedia Fintech News

OpenClaw’s fast-growing plugin store, ClawHub, is under security spotlight after blockchain security firm SlowMist uncovered a large batch of malicious skills on the platform. 

The finding points to weak review checks that allowed hidden, harmful code to spread through developer tools.

OpenClaw ClawHub Plugin Faces Supply Chain Attack Risk

SlowMist revealed that OpenClaw’s official plugin hub, known as ClawHub, has become a new target for supply chain-style attacks. The platform recently gained rapid popularity among AI agent developers, but its plugin screening process did not keep pace with growth.

Because plugin reviews were not strict enough, attackers were able to publish many dangerous skills that looked useful on the surface but carried hidden risks.

SlowMist teams say this type of attack is especially risky because developers often trust official plugin centers and follow installation steps without deep inspection.

341 Malicious Plugins Expose

During a broad scan of the ClawHub ecosystem, security researchers found a high number of unsafe plugins. A separate scan by Koi Security reviewed 2,857 skills and flagged 341 as malicious.

SlowMist’s deeper tracking reviewed more than 400 threat indicators and found clear patterns, many of the bad plugins connected back to the same small group of domains and server addresses. 

OpenClaw ClawHub plugin

However, Slowmist says that this suggests an organized and repeated attack effort, not random uploads.

How the Attack Actually Works?

According to the researchers, the main weakness comes from how OpenClaw skills are built. Many rely on instruction files that users run directly during setup. Attackers abused this by placing hidden download-and-run commands inside those instructions.

In many cases, the first attackers used coded messages to hide their real commands. When the code is decoded and run, it secretly downloads another program from an outside server. Secondly, that program then carries out the actual attack.

This two-step method helps attackers avoid early detection and lets them change the harmful program anytime without updating the visible plugin page.

Malicious Domain Analysis

SlowMist said its review of hundreds of threat indicators showed many of these plugins connected to the same small set of domains and IP addresses, 91.92.242.30. This suggests a planned, group-driven campaign rather than random one-off attacks.

Security teams are now warning OpenClaw users to double-check skill instructions and avoid running unknown command steps until stronger review controls are in place.

Piyasa Fırsatı
OpenClaw Logosu
OpenClaw Fiyatı(OPENCLAW)
$0.0003019
$0.0003019$0.0003019
-0.39%
USD
OpenClaw (OPENCLAW) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

ETH Exit Queue Gridlocks As Validators Pile Up

ETH Exit Queue Gridlocks As Validators Pile Up

The post ETH Exit Queue Gridlocks As Validators Pile Up appeared on BitcoinEthereumNews.com. Welcome to The Protocol, CoinDesk’s weekly wrap of the most important stories in cryptocurrency tech development. I’m Margaux Nijkerk, a reporter at CoinDesk. In this issue: Ethereum Faces Validator Bottleneck With 2.5M ETH Awaiting Exit Is Ethereum’s DeFi Future on L2s? Liquidity, Innovation Say Perhaps Yes Ethereum Foundation Starts New AI Team to Support Agentic Payments American Express Introduces Blockchain-Based ‘Travel Stamps’ Network News ETHEREUM VALIDATOR EXIT QUEUE FACES BOTTLENECK: Ethereum’s proof-of-stake system is facing its largest test yet. As of mid-September, roughly 2.5 million ETH — valued at roughly $11.25 billion — is waiting to leave the validator set, according to validator queue dashboards. The backlog pushed exit wait times to more than 46 days on Sept. 14, the longest in Ethereum’s short staking history, dashboards show. The last peak, in August, put the exit queue at 18 days. The initial spark came on Sept. 9, when Kiln, a large infrastructure provider, chose to exit all of its validators as a safety precaution. The move, triggered by recent security incidents including the NPM supply-chain attack and the SwissBorg breach, pushed around 1.6 million ETH into the queue at once. Though unrelated to Ethereum’s staking protocol itself, the hacks rattled confidence enough for Kiln to hit pause, highlighting how events in the broader crypto ecosystem can cascade into Ethereum’s validator dynamics. In a blog post from staking provider Figment, Senior Analyst Benjamin Thalman noted that the current exit queue build up isn’t only about security. After ETH has rallied more than 160% since April, some stakers are simply taking profits. Others, especially institutional players, are shifting their portfolios’ exposure. At the same time, the number of validators entering the Ethereum staking ecosystem has been steadily rising. Ethereum’s churn limit, which is a protocol safeguard that caps how many validators can…
Paylaş
BitcoinEthereumNews2025/09/18 15:15
TheWell Bioscience Launches VitroPrime™ 3D Culture and Imaging Plate for Organoid and 3D Cell Culture Workflows

TheWell Bioscience Launches VitroPrime™ 3D Culture and Imaging Plate for Organoid and 3D Cell Culture Workflows

A new in-plate, zero-disruption design enables reproducible organoid culture, downstream processing, and high-resolution imaging in a single 3D cell culture plate
Paylaş
AI Journal2026/02/09 22:02
Tom Lee Linked BitMine Scoops Up $82 Million in Ethereum as Institutional Appetite Heats Up

Tom Lee Linked BitMine Scoops Up $82 Million in Ethereum as Institutional Appetite Heats Up

Tom Lee–Backed BitMine Makes $82 Million Ethereum Purchase, Signaling Growing Institutional Confidence BitMine, a crypto-focused firm associated with veteran ma
Paylaş
Hokanews2026/02/09 22:08