logo

OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware

ID: dc96ee97-10e2-5e5f-b738-67ba46cd1cc4

STIX ID: report--dc96ee97-10e2-5e5f-b738-67ba46cd1cc4

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Abinaya

...
...

VirusTotal uncovered a large malware distribution campaign targeting the OpenClaw AI-agent ecosystem, where hundreds of third-party "skills" on the ClawHub marketplace instruct users to download and run external code or obfuscated scripts, leading to trojans and the Atomic Stealer (AMOS) infostealer; one publisher was linked to 314 malicious skills. The report warns that skills run with full system access, recommends treating skill folders as trusted-code boundaries, sandboxing execution, and adding publish-time scanning for remote execution and obfuscation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.