logo

OpenClaw Integrates VirusTotal Scanning to Detect Malicious ClawHub Skills

ID: b0f6a364-1dfc-570b-8d50-c4b8ace0bde0

STIX ID: report--b0f6a364-1dfc-570b-8d50-c4b8ace0bde0

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-02-08

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

OpenClaw (formerly Moltbot/Clawdbot) and its ClawHub/Moltbook ecosystem have been found to contain numerous security flaws and active malicious content: researchers discovered hundreds of malicious skills capable of data exfiltration and backdoors, prompt-injection and zero-click attack chains that enable persistent remote control, a one-click RCE and other vulnerabilities, widespread misconfigurations with 30,000+ exposed instances, and an exposed Moltbook Supabase database leaking ~1.5 million API tokens — collectively creating a high-risk, large-scale threat to users and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.