logo

Securing OpenClaw Against “ClawHavoc”

ID: 3bb285f4-a913-55a1-bacc-f6729f077738

STIX ID: report--3bb285f4-a913-55a1-bacc-f6729f077738

Feed Name: Aryaka

Threat Score
85/100

Date Published: 2026-02-18

Date Updated: 2026-04-27

Author: Srini Addepalli

...
...

As of Feb 2026, a supply-chain campaign dubbed “ClawHavoc” abused OpenClaw agent skills by embedding malicious SKILL.md manifests that tricked agents and users into running remote installer commands, which fetched infostealer payloads (Atomic Stealer/AMOS and keyloggers) that exfiltrate cookies, keys and wallet data; researchers found roughly 12% of ClawHub skills were malicious. The report also analyzes OpenClaw’s elevated attack surface (system access, untrusted ingestion, autonomous egress) and describes how an AI-aware MITM proxy (Aryaka AI>Secure) can mitigate the threat via Markdown/semantic inspection, LLM response filtering, URL/SWG blocking and runtime DLP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.