logo

Poisoning the well: AI supply chain attacks on Hugging Face and OpenClaw

ID: 08153a7f-df12-5673-aeba-7279facce03b

STIX ID: report--08153a7f-df12-5673-aeba-7279facce03b

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-07-24

...
...

**Executive Summary:** Acronis TRU uncovered large-scale abuse of AI distribution ecosystems (OpenClaw/ClawHub and Hugging Face) where attackers publish trojanized skills, models and repositories to distribute malware — including AMOS infostealer, cryptominers and loaders — leveraging social engineering, indirect prompt injection, obfuscated binaries, in-memory execution and covert C2; investigators identified 575+ malicious OpenClaw skills across 13 developer accounts, documented active campaigns (ITHKRPAW, FAKESECURITY), provided numerous IOCs and recommended mitigations such as strict application control, monitoring and vetting of AI artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.