logo

Abuse of OpenClaw AI Capabilities Enables Stealthy Malware Campaigns

ID: 053adcee-5e18-5721-8100-61adc5e6f36f

STIX ID: report--053adcee-5e18-5721-8100-61adc5e6f36f

Feed Name: GBHackers

Threat Score
82/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Divya

...
...

OpenClaw's ClawHub marketplace is being weaponized as a supply-chain distribution channel: VirusTotal analyzed thousands of skills and identified hundreds (314 attributed to one publisher) that deploy droppers, backdoors, and infostealers—Windows users receive packed Trojan EXEs while macOS users get obfuscated scripts that retrieve Atomic Stealer; the report highlights behavioral detection by VirusTotal, and recommends sandboxing OpenClaw, scanning community skills, and implementing publish-time checks to block remote-execution and obfuscated code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.