Poisoning the well: AI supply chain attacks on Hugging Face and OpenClaw
ID: 08153a7f-df12-5673-aeba-7279facce03b
STIX ID: report--08153a7f-df12-5673-aeba-7279facce03b
Feed Name: TRU Security by Acronis
**Executive Summary:** Acronis TRU uncovered large-scale abuse of AI distribution ecosystems (OpenClaw/ClawHub and Hugging Face) where attackers publish trojanized skills, models and repositories to distribute malware — including AMOS infostealer, cryptominers and loaders — leveraging social engineering, indirect prompt injection, obfuscated binaries, in-memory execution and covert C2; investigators identified 575+ malicious OpenClaw skills across 13 developer accounts, documented active campaigns (ITHKRPAW, FAKESECURITY), provided numerous IOCs and recommended mitigations such as strict application control, monitoring and vetting of AI artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
