ClawHub AI Agent Skill Marketplace Supply‑Chain Attack via OpenClaw Malware
Threat actors published malicious AI‑agent skills on the ClawHub marketplace that masquerade as legitimate Google‑assistant‑style plugins. The OpenClaw skill uses a benign JSON manifest to import a hidden Python module that generates obfuscated C2 code at runtime via LLM‑prompted execution, evading static and dynamic scanners. Over 340 malicious skills were discovered, amassing ~410 k downloads and affecting >120 enterprises that rely on AI‑agent frameworks, enabling credential exfiltration and potential downstream propagation through agent compositions.
- Incident Overview: Scope and Discovery
- ClawHub hosted >340 AI agent skills; 341 identified as malicious (OpenClaw family) as of ClawTrust blog.
- Estimated total downloads ≈ 410 k, with ~1.2 k daily downloads per malicious skill.
- Affected organizations exceed 120 enterprises using AI‑agent development kits or orchestration platforms.
-
Multiple credential‑theft incidents reported by Snyk and Unit 42 telemetry.
-
Attack Vector: How OpenClaw Evades Detection
- Manifest (
skill.json) lacks a cryptographic signature, allowing unsigned publication. - Embedded Base64‑encoded payload decoded via
exec(base64.b64decode(...))at runtime. - Dynamic LLM‑driven code generation: prompts sent to
openai.Completion.createproduce obfuscated C2 routines. - Skill versioning toggles benign/malicious implementations based on environment variables, thwarting signature‑based scanners.
-
No provenance verification in the marketplace index enables automatic pull of tainted skills by dependent agents.
-
Threat Actor Profile and Campaign Scale
- Attribution points to financially motivated groups leveraging AI‑agent ecosystems for supply‑chain intrusion.
- Campaign leverages the novelty of agentic behavior to bypass traditional AV/EDR that focus on static binaries.
- Estimated CVSS ≈ 8.2 (High) due to remote code execution and data exfiltration capabilities.
-
Mitigation efforts by marketplace operators (skill signing, sandboxing) cover <40% of published skills.
-
Indicators of Compromise and Defensive Actions
- IoC: Manifest URL
https://clawtrust.ai/skills/openclaw. - IoC: Presence of
exec(base64.b64decode(...))patterns in skill‑associated Python modules. - IoC: Outbound HTTPS calls to atypical domains linked to
openai.Completion.createwith user‑controlled prompts. - Recommended defenses: enforce skill signing, validate
signaturefield, isolate agent runtimes in sandboxes, monitor for dynamic LLM API usage, and block downloads from unverified ClawHub endpoints. -
Deploy YARA rule matching Base64‑decoded payloads and anomalous
openai.Completion.createcall patterns. -
Conclusion: Implications for AI‑Agent Supply Chains
- The ClawHub incident demonstrates that AI‑agent skill repositories replicate npm‑style supply‑chain risks, amplified by LLM‑driven runtime behavior.
- Organizations must treat third‑party agent skills as untrusted code, applying strict provenance, sandboxing, and runtime monitoring.
- Marketplace operators should enforce mandatory signing, automated static/dynamic analysis of skill code, and version‑integrity checks.
- Continued threat‑modeling of agentic attack surfaces is essential as AI‑agent adoption expands across DevOps and automation pipelines.
Related posts
- techjacksolutions.com — AI Agent Skill Marketplaces Are the New npm: ClawHub Malware Bypasses Automated Scanners With Novel Agentic Attack Techniques
- Thenextweb
- Snyk
- Skywork
- Arxiv
- Unit42
- Penligent
- Xcloud
- Clawtrust