The post OpenClaw’s ClawHub Flags 1,184 Malicious Skills appeared on BitcoinEthereumNews.com. Key Highlights: Security researchers flagged 1,184 malicious “skillsThe post OpenClaw’s ClawHub Flags 1,184 Malicious Skills appeared on BitcoinEthereumNews.com. Key Highlights: Security researchers flagged 1,184 malicious “skills

OpenClaw’s ClawHub Flags 1,184 Malicious Skills

For feedback or concerns regarding this content, please contact us at [email protected]

Key Highlights:

  • Security researchers flagged 1,184 malicious “skills” on OpenClaw’s ClawHub capable of stealing SSH keys, wallet data, and browser credentials.
  • A single attacker uploaded hundreds of harmful packages, some of which were downloaded widely before being detected.
  • Experts warn that rapid adoption of OpenClaw tools is outpacing security safeguards, increasing risks of credential theft and remote code execution.

The OpenClaw ecosystem is yet again under fire for security reasons, this time due to its official marketplace, ClawHub. Researchers have identified 1184 malicious packages circulating in ClawHub.

The warning was highlighted by SlowMist founder Cosmos Yu, who shared details of the issue.

OpenClaw’s ClawHub in the Crosshairs for Security Concerns

According to the alert, a total of 1,184 malicious “skills” have been detected on ClawHub. These packages are capable of stealing SSH keys, extracting browser passwords, encrypting wallets, and even opening reverse shells on user machines. In one case, a single attacker was responsible for uploading 677 separate packages into the marketplace.

Some of these skills had already gained traction. The highest-ranked malicious package reportedly has nine separate vulnerabilities and had been downloaded thousands of times before being flagged. This raises questions about how quickly harmful code can spread across decentralized or semi-open AI agent ecosystems where discoverability is high and review processes may lag behind adoption.

ClawHub is the official skill registry for OpenClaw. It functions similarly to a package manager for AI agents, allowing developers and users to extend functionality through downloadable modules. At the time of writing, the registry listed 3,286 skills across 11 categories and had seen more than 1.5 million downloads. Its vector-based semantic search allows users to find tools using natural language queries, which improves usability but may also increase exposure to unsafe packages if moderation is insufficient.

The platform has already faced security issues in recent weeks. Earlier this month, researchers documented a “ClawHavoc” incident involving hundreds of malicious skills designed to steal user data. In response, the platform removed more than 2,400 suspicious packages, introduced automated malware scanning through a partnership with VirusTotal, and strengthened moderation rules so that flagged tools are hidden after multiple reports. A user reporting system for unsafe skills has also been introduced.

Even with these measures, the OpenClaw ecosystem continues to draw criticism. The platform, which previously operated under names including Clawdbot and Moltbot, has been described by security researchers as innovative but highly exposed to risk. Cisco Talos recently called it groundbreaking for productivity and also labeled it a major security challenge.

At the same time, the platform’s rapid growth in crypto sector has intensified the risks. OpenClaw agents can directly interact with blockchain networks like Polygon and Solana. They can also communicate with other agents and execute tasks autonomously. These features around financial capability, automation, and networked coordination has accelerated its adoption among both developers and crypto users. Some users have already reported generating trading profits through arbitrage and prediction market strategies using these agents.

However, security analysts say adoption is outpacing governance. Researchers have observed attackers scanning for default OpenClaw ports and testing ways to dodge protections. Enterprise security providers have also warned that a large number of employees are deploying these tools internally without formal approval. This pattern mirrors the wider rise of shadow IT, where new technologies spread faster than internal controls can keep up.

Yu has warned that in the age of AI agents, text inputs can function as executable commands. He advised users to run such tools in isolated environments and to treat third-party skills with caution. He also pointed out that Web3 security risks are no longer limited to smart contracts alone, as he cited recent incidents where vulnerabilities introduced via AI-assisted code contributed to losses.

Also Read: Moonwell: Recovery Plan Moves to Governance Forum Following 2.68M Loss

Source: https://www.cryptonewsz.com/openclaws-clawhub-flags-1184-malicious-skills/

Market Opportunity
Ucan fix life in1day Logo
Ucan fix life in1day Price(1)
$0.0005309
$0.0005309$0.0005309
+1.80%
USD
Ucan fix life in1day (1) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

U.S. Oil Production Is On Pace For A New Record, But Growth Is Slowing

U.S. Oil Production Is On Pace For A New Record, But Growth Is Slowing

The post U.S. Oil Production Is On Pace For A New Record, But Growth Is Slowing appeared on BitcoinEthereumNews.com. FORT STOCKTON, TEXAS – MARCH 24: The sun sets behind a pumpjack during a gusty night on March 24, 2024 in Fort Stockton, Texas. Employment in Texas has reached record highs, with the oil- and gas-producing Permian Basin, which covers a large swathe of west Texas, leading the way. Permian Basin towns of Midland and Odessa notched 2.6 and 3.5 percent unemployment respectively, according to the report touted earlier this month by Gov. Gregg Abbott. (Photo by Brandon Bell/Getty Images) Getty Images For the past two years, the United States has set oil production records. This growth is a continuance of the surge in oil production resulting from the shale boom that began earlier this century. According to data from the Energy Information Administration, U.S. oil production average 13.2 million barrels per day in 2024, up from 12.7 million in 2023 and 12.5 million in 2022. U.S. Oil Production 1860-2024. Energy Information Administration It is now clear that the U.S. is on track this year to set its third consecutive annual record for crude oil production. Year-to-date production through the week ending September 12, 2025 shows a production level of 13.44 million BPD, which is about 1.9% ahead of last year’s record pace. But beneath those headline numbers, a subtle shift is underway: growth is slowing. The slowdown becomes clear if we look at the year-over-year percentage changes over the past 20 years. Annual Oil Production Change 2006-2025 YTD. Robert Rapier There have been only two other periods in the past 20 years where U.S. oil production growth slowed for three consecutive years, but both of those instances had extenuating circumstances. The first was from 2014 through 2016, when a price war launched by OPEC triggered a collapse in oil prices and forced U.S. producers to slash drilling activity. The…
Share
BitcoinEthereumNews2025/09/18 18:35
Silver Prices Edge Closer to a Pivotal Support and Resistance Test

Silver Prices Edge Closer to a Pivotal Support and Resistance Test

The post Silver Prices Edge Closer to a Pivotal Support and Resistance Test appeared on BitcoinEthereumNews.com. The silver market, although experiencing recent
Share
BitcoinEthereumNews2026/03/07 11:29
[Newspoint] Overpaid troll

[Newspoint] Overpaid troll

KAUFMAN. Former president Rodrigo Duterte's lawyer Nicholas Kaufman delivers his opening statement before the ICC Pre-Trial Chamber I on February 23, 2026.
Share
Rappler2026/03/07 11:00