FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

ClawHub AI Agent Skill Marketplace Supply‑Chain Attack via OpenClaw Malware

Threat actors published malicious AI‑agent skills on the ClawHub marketplace that masquerade as legitimate Google‑assistant‑style plugins. The OpenClaw skill uses a benign JSON manifest to import a hidden Python module that generates obfuscated C2 code at runtime via LLM‑prompted execution, evading static and dynamic scanners. Over 340 malicious skills were discovered, amassing ~410 k downloads and affecting >120 enterprises that rely on AI‑agent frameworks, enabling credential exfiltration and potential downstream propagation through agent compositions.


LINK COPIED TO CLIPBOARD