Abuse of OpenClaw AI Capabilities Enables Stealthy Malware Campaigns
ID: 053adcee-5e18-5721-8100-61adc5e6f36f
STIX ID: report--053adcee-5e18-5721-8100-61adc5e6f36f
Feed Name: GBHackers
OpenClaw's ClawHub marketplace is being weaponized as a supply-chain distribution channel: VirusTotal analyzed thousands of skills and identified hundreds (314 attributed to one publisher) that deploy droppers, backdoors, and infostealers—Windows users receive packed Trojan EXEs while macOS users get obfuscated scripts that retrieve Atomic Stealer; the report highlights behavioral detection by VirusTotal, and recommends sandboxing OpenClaw, scanning community skills, and implementing publish-time checks to block remote-execution and obfuscated code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
