Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap
ID: d9bbdcc2-7df7-5560-8692-6e5ddfbf0f59
STIX ID: report--d9bbdcc2-7df7-5560-8692-6e5ddfbf0f59
Feed Name: Bitdefender Labs
Bitdefender Labs uncovered a large-scale campaign abusing OpenClaw skills to distribute malicious code and harvest credentials—about 17% of analyzed skills in early February 2026 exhibited malicious behavior. Attackers clone and republish crypto-focused utilities and maintenance/updater skills to trick users into running Base64-obfuscated shell commands that fetch payloads (hosted repeatedly from 91.92.242.30, paste services, and impersonating GitHub repos), delivering macOS AMOS Stealer and silent exfiltration tools that target private keys, API tokens, and social accounts; the campaign impacts consumers and enterprises and the report recommends treating skills like software installs, avoiding external binaries, isolating crypto tooling, and using security solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
