ClawHub may be hosting supply chain attacks through new AI agent skills. Some of the skills contain malware to steal credentials and potentially affect accountsClawHub may be hosting supply chain attacks through new AI agent skills. Some of the skills contain malware to steal credentials and potentially affect accounts

ClawHub hosts AI agent skills enabling supply chain attacks

2026/02/09 17:10
Okuma süresi: 3 dk

ClawHub may be hosting supply chain attacks through new AI agent skills. Some of the skills contain malware to steal credentials and potentially affect accounts and crypto wallets. 

ClawHub, the marketplace for OpenClaw AI agent skills, is hosting multiple malicious skills. The supply chain attack may be stealing credentials, potentially affecting crypto wallets. 

ClawHub hosts AI agent skills enabling supply chain attacks

Security researchers from SlowMist reviewed over 400 potential compromised skills, revealing organized attacks targeting specific domains. Skills like X Trends hide a backdoor download, which can then send credentials to the threat actor. 

The SlowMist research builds on a previous discovery by KOI Security, discovering 341 malicious skills among a total of 2,857 bot skills in the marketplace. Later analysis by SlowMist discovered up to 472 malicious skills, though the number can still vary.

ClawHub conceals stealers in hundreds of skills

Earlier, Koi Research conducted AI-assisted research using an OpenClaw bot named Alex. The bot found 335 skills that were used to push the Atomic Stealer on macOS. 

You install what looks like a legitimate skill – maybe solana-wallet-tracker or youtube-summarize-pro,” Koi researcher Oren Yomtov said. 

“The skill’s documentation looks professional. But there’s a ‘Prerequisites’ section that says you need to install something first.”

A Windows exploit is also active, calling users to download additional files from a GitHub repository. The supply chain attack also includes a keylogger, which can steal multiple credentials, including potentially uncovering crypto wallets. 

As Cryptopolitan reported earlier, OpenClaw agents are still in their early stages and are displaying unexpected behavior. Adoption is growing daily, posing new risks in cybersecurity and agent behaviors.

SlowMist continues tracking ClawHub skills for new threats

The recent supply chain attack may not be a one-off event. ClawHub is a relatively new space, attracting a large number of developers. SlowMist will be tracking the space as a source of supply chain attacks. The platform still lacks formal review mechanisms, allowing widely used skills to be infiltrated. 

There are still no clear reports of crypto theft through ClawHub. Previously, the public skills repo has contained malicious prompts linked to attempted crypto stealing. In the future, SlowMist will issue real-time alerts via its MistEye service to detect new malicious skills on ClawHub.

SlowMist has also identified an IP address that is reused in the malicious attacks. According to theat records, the IP 91.92.242.30 is historically linked to the Poseidon hacker group, known for extortion and data theft.

For end users, researchers advise against trusting the installation steps in new skills and to audit any commands that require copying and pasting. A common-sense preview of prompts is also a good check, looking for prompts asking for system passwords or other secure access. Users may wait for official channels and avoid installations from unknown sources.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Piyasa Fırsatı
Hyperbot Logosu
Hyperbot Fiyatı(BOT)
$0.001773
$0.001773$0.001773
-8.32%
USD
Hyperbot (BOT) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Fan Token Firm Chiliz Acquires 2-Time ‘Dota 2’ Champions, OG Esports

Fan Token Firm Chiliz Acquires 2-Time ‘Dota 2’ Champions, OG Esports

The post Fan Token Firm Chiliz Acquires 2-Time ‘Dota 2’ Champions, OG Esports appeared on BitcoinEthereumNews.com. In brief The Chiliz Group has acquired a controlling stake in OG Esports, a prominent competitive gaming organization. OG Esports unveiled its own fan token on Chiliz’s Socios.com platform back in 2020. It recently hit an all-time high price. Chiliz has teased various future team-related benefits for OG token holders, along with a new Web3-related project. The Chiliz Group, which operates the Socios.com crypto fan token platform, announced Tuesday that it has acquired a 51% controlling stake in OG Esports, the competitive gaming organization founded in 2015 by Dota 2 legends Johan “nOtail” Sundstein and Sébastien “Ceb” Debs. OG made history as the first team to win consecutive titles at The International—the annual, high-profile Dota 2 world championship tournament—in 2018 and 2019, and has since expanded into multiple games including Counter-Strike, Honor of Kings, and Marvel Rivals. The team was also the first esports organization to join the Socios platform with the 2020 debut of its own fan token, which Chiliz said recently became the first esports team token to exceed a $100 million market capitalization. OG was recently priced at $16.88, up nearly 9% on the day following the announcement. The token’s price peaked at a new all-time high of $24.78 last week ahead of The International 2025, where OG did not compete this year. Following the acquisition, Xavier Oswald will assume the CEO role, while the co-founders will turn their attention to “a new strategic project consolidating the team’s competitive foundation [and] driving innovation at the intersection of esports and Web3,” per a press release. No further details were provided regarding that project. “Bringing OG into the Chiliz Group is a major step toward further strengthening fan experiences, one where the community doesn’t just watch from the sidelines but gets to shape the journey,” Chiliz CEO Alex Dreyfus…
Paylaş
BitcoinEthereumNews2025/09/18 09:40
Travelzoo Q4 2025 Earnings Conference Call on February 19 at 11:00 AM ET

Travelzoo Q4 2025 Earnings Conference Call on February 19 at 11:00 AM ET

NEW YORK, Feb. 9, 2026 /PRNewswire/ — Travelzoo® (NASDAQ: TZOO): WHAT: Travelzoo, the club for travel enthusiasts, will host a conference call to discuss the Company
Paylaş
AI Journal2026/02/10 01:46
Trump Backs Bitcoin As New Safe Haven

Trump Backs Bitcoin As New Safe Haven

On CNBC, Eric Trump stated that Bitcoin has "taken the role of gold in today’s world," elevating crypto to the status of a strategic safe haven asset. This media appearance coincides with the launch of American Bitcoin, a mining and BTC holding company he is close to. Far from a mere announcement, this statement fits within a dynamic where publicly traded companies are beginning to integrate bitcoin at the heart of their reserve strategy. L’article Trump Backs Bitcoin As New Safe Haven est apparu en premier sur Cointribune.
Paylaş
Coinstats2025/09/18 14:32