logo

MoltBot Skills exploited to distribute 400+ malware packages in days

ID: e1e921bf-9a4f-5187-bf94-25630e67fd03

STIX ID: report--e1e921bf-9a4f-5187-bf94-25630e67fd03

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-02-02

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Over 400 malicious OpenClaw (formerly MoltBot/ClawdBot) skills were published on ClawHub and GitHub between late January and early February 2026, masquerading as cryptocurrency trading tools to trick users into running commands that installed information‑stealing malware on Windows and macOS. The campaign—dominated by a single uploader and reusing a common C2 infrastructure—exploited weak registry review and social engineering, constituting a supply-chain style attack against the emerging AI skills ecosystem and targeting crypto traders for financial gain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.