Malicious OpenClaw Skill Targets DeepSeek Agentic AI Workflows
ID: 6aed90df-09c0-5dc2-90a8-4b38a794258d
STIX ID: report--6aed90df-09c0-5dc2-90a8-4b38a794258d
Feed Name: Cyber Press
Zscaler ThreatLabz uncovered a March 2026 supply-chain malware campaign that abused the OpenClaw framework by publishing a malicious "DeepSeek-Claw" plugin which installs Remcos RAT on Windows (via a signed MSI and DLL side-loading) and a GhostLoader infostealer on macOS/Linux (via obfuscated Node.js lifecycle scripts and social-engineered password prompts), targeting AI agent workflows and developer environments to harvest credentials, SSH keys, wallets and API tokens; indicators and malicious URLs/repositories are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
