logo

Malicious MoltBot skills used to push password-stealing malware

ID: 89d33a1e-a56d-5dbb-b817-8ff8b9e2bbb6

STIX ID: report--89d33a1e-a56d-5dbb-b817-8ff8b9e2bbb6

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers found 230–341 malicious OpenClaw skills published on the official registry and GitHub that impersonate legitimate plugins but instruct users to run a malicious 'AuthTool' which installs info-stealing malware (including a NovaStealer variant). The campaign targets cryptocurrency-related secrets, browser and system credentials across macOS and Windows, uses techniques to bypass macOS Gatekeeper, and exploits misconfigured exposed admin interfaces; users are advised to isolate the assistant, restrict permissions, and verify skill safety before deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.