logo

Malicious OpenClaw Skill Targets DeepSeek Agentic AI Workflows

ID: 6aed90df-09c0-5dc2-90a8-4b38a794258d

STIX ID: report--6aed90df-09c0-5dc2-90a8-4b38a794258d

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Varshini

...
...

Zscaler ThreatLabz uncovered a March 2026 supply-chain malware campaign that abused the OpenClaw framework by publishing a malicious "DeepSeek-Claw" plugin which installs Remcos RAT on Windows (via a signed MSI and DLL side-loading) and a GhostLoader infostealer on macOS/Linux (via obfuscated Node.js lifecycle scripts and social-engineered password prompts), targeting AI agent workflows and developer environments to harvest credentials, SSH keys, wallets and API tokens; indicators and malicious URLs/repositories are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.