logo

OpenClaw Becomes New Target in Rising Wave of Supply Chain Poisoning Attacks

ID: e7bf23a6-2c51-5c39-acd7-c6565279a336

STIX ID: report--e7bf23a6-2c51-5c39-acd7-c6565279a336

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-09

Date Updated: 2026-04-21

Author: Guru Baran

...
...

OpenClaw's ClawHub skill marketplace is being abused in a supply‑chain campaign (ClawHavoc) where malicious SKILL.md prerequisites contain Base64‑encoded commands that execute curl|bash droppers; these fetch two‑stage payloads and macOS infostealers (Atomic/AMOS) that exfiltrate documents and credentials. Security firms Koi Security and SlowMist identified hundreds of compromised skills, detailed TTPs (obfuscated prerequisites, two‑stage downloads, phishing dialogs), and provided extensive IOCs (domains, IPs, URLs, and SHA256 file hashes) for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.