Malicious MoltBot skills used to push password-stealing malware
ID: 89d33a1e-a56d-5dbb-b817-8ff8b9e2bbb6
STIX ID: report--89d33a1e-a56d-5dbb-b817-8ff8b9e2bbb6
Feed Name: Bleeping Computer
Researchers found 230–341 malicious OpenClaw skills published on the official registry and GitHub that impersonate legitimate plugins but instruct users to run a malicious 'AuthTool' which installs info-stealing malware (including a NovaStealer variant). The campaign targets cryptocurrency-related secrets, browser and system credentials across macOS and Windows, uses techniques to bypass macOS Gatekeeper, and exploits misconfigured exposed admin interfaces; users are advised to isolate the assistant, restrict permissions, and verify skill safety before deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
