OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud
ID: ec8f7347-2f72-5f6a-9013-98630ad8539f
STIX ID: report--ec8f7347-2f72-5f6a-9013-98630ad8539f
Feed Name: cybersecurityNews.com
Unit 42 / CSN analysis documents a campaign of malicious third-party skills on the OpenClaw ClawHub marketplace that delivered macOS infostealers, an AMOS dropper (file-padded to evade scanners), and two agentic skills used for affiliate injection and coordinated pump-and-dump financial fraud; attackers abused the agents' instruction-following behavior and authenticated sessions to execute payloads and covertly modify recommendations. The report provides IoCs (IPs, domains, URLs, GitHub repo, and multiple SHA256 hashes), describes evasion and delivery techniques, and recommends publisher validation, source audits, and outbound traffic monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
