OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware
ID: dc96ee97-10e2-5e5f-b738-67ba46cd1cc4
STIX ID: report--dc96ee97-10e2-5e5f-b738-67ba46cd1cc4
Feed Name: cybersecurityNews.com
VirusTotal uncovered a large malware distribution campaign targeting the OpenClaw AI-agent ecosystem, where hundreds of third-party "skills" on the ClawHub marketplace instruct users to download and run external code or obfuscated scripts, leading to trojans and the Atomic Stealer (AMOS) infostealer; one publisher was linked to 314 malicious skills. The report warns that skills run with full system access, recommends treating skill folders as trusted-code boundaries, sandboxing execution, and adding publish-time scanning for remote execution and obfuscation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
