← Back to Daily Briefing (#Clawhub)

ClawHub AI Agent Skill Marketplace Supply‑Chain Attack via OpenClaw Malware

Published September 28, 2026

Threat actors published malicious AI‑agent skills on the ClawHub marketplace that masquerade as legitimate Google‑assistant‑style plugins. The OpenClaw skill uses a benign JSON manifest to import a hidden Python module that generates obfuscated C2 code at runtime via LLM‑prompted execution, evading static and dynamic scanners. Over 340 malicious skills were discovered, amassing ~410 k downloads and affecting >120 enterprises that rely on AI‑agent frameworks, enabling credential exfiltration and potential downstream propagation through agent compositions.

  • Incident Overview: Scope and Discovery
  • ClawHub hosted >340 AI agent skills; 341 identified as malicious (OpenClaw family) as of ClawTrust blog.
  • Estimated total downloads ≈ 410 k, with ~1.2 k daily downloads per malicious skill.
  • Affected organizations exceed 120 enterprises using AI‑agent development kits or orchestration platforms.
  • Multiple credential‑theft incidents reported by Snyk and Unit 42 telemetry.

  • Attack Vector: How OpenClaw Evades Detection

  • Manifest (skill.json) lacks a cryptographic signature, allowing unsigned publication.
  • Embedded Base64‑encoded payload decoded via exec(base64.b64decode(...)) at runtime.
  • Dynamic LLM‑driven code generation: prompts sent to openai.Completion.create produce obfuscated C2 routines.
  • Skill versioning toggles benign/malicious implementations based on environment variables, thwarting signature‑based scanners.
  • No provenance verification in the marketplace index enables automatic pull of tainted skills by dependent agents.

  • Threat Actor Profile and Campaign Scale

  • Attribution points to financially motivated groups leveraging AI‑agent ecosystems for supply‑chain intrusion.
  • Campaign leverages the novelty of agentic behavior to bypass traditional AV/EDR that focus on static binaries.
  • Estimated CVSS ≈ 8.2 (High) due to remote code execution and data exfiltration capabilities.
  • Mitigation efforts by marketplace operators (skill signing, sandboxing) cover <40% of published skills.

  • Indicators of Compromise and Defensive Actions

  • IoC: Manifest URL https://clawtrust.ai/skills/openclaw.
  • IoC: Presence of exec(base64.b64decode(...)) patterns in skill‑associated Python modules.
  • IoC: Outbound HTTPS calls to atypical domains linked to openai.Completion.create with user‑controlled prompts.
  • Recommended defenses: enforce skill signing, validate signature field, isolate agent runtimes in sandboxes, monitor for dynamic LLM API usage, and block downloads from unverified ClawHub endpoints.
  • Deploy YARA rule matching Base64‑decoded payloads and anomalous openai.Completion.create call patterns.

  • Conclusion: Implications for AI‑Agent Supply Chains

  • The ClawHub incident demonstrates that AI‑agent skill repositories replicate npm‑style supply‑chain risks, amplified by LLM‑driven runtime behavior.
  • Organizations must treat third‑party agent skills as untrusted code, applying strict provenance, sandboxing, and runtime monitoring.
  • Marketplace operators should enforce mandatory signing, automated static/dynamic analysis of skill code, and version‑integrity checks.
  • Continued threat‑modeling of agentic attack surfaces is essential as AI‑agent adoption expands across DevOps and automation pipelines.

Related posts

  1. techjacksolutions.com — AI Agent Skill Marketplaces Are the New npm: ClawHub Malware Bypasses Automated Scanners With Novel Agentic Attack Techniques
  2. Thenextweb
  3. Snyk
  4. Skywork
  5. Arxiv
  6. Unit42
  7. Penligent
  8. Xcloud
  9. Clawtrust

LINK COPIED TO CLIPBOARD