CampaignStatus unknownCoverage: Partly coveredPrimary source

“AuthTool” trading skills

Reported by Koi Security on . Names, numbers, and dates are as the sources state them.

What it did

Crypto-trading skills that required a fake “AuthTool”: a password-protected archive from GitHub on Windows, and an obfuscated command on macOS that fetched code from the shared raw IP address.

Skill names as reported

  • base-agent
  • bybit-agent
  • polymarket-traiding-bot

Techniques

  • Fake prerequisite
  • Password-protected archive
  • Encoded command
  • Download piped to shell

Status, as stated by the source

No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which.

We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.

Would Ironheights flag this pattern?

Partly covered

The macOS decode-and-run line is flagged by IH-EXEC-001 and its decoy host by IH-NET-001. The Windows archive link on GitHub is not flagged.

Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.

Sources

  1. ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting(opens in a new tab)Koi Security (Internet Archive copy, 10 February 2026) · primaryThe original koi.ai address now redirects to a Palo Alto Networks product page, so we link the archived copy.
  2. Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap(opens in a new tab)Bitdefender Labs · primary

Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.

Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.