StudyStatus unknownCoverage: Not assessedPrimary source

Bitdefender Labs analysis of OpenClaw skills

Published by Bitdefender Labs on . Names, numbers, and dates are as the sources state them.

What the study found

Found about 17% of the OpenClaw skills it analyzed in the first week of February 2026 behaving maliciously, 54% of those crypto-themed. It tied 199 skills to one publisher, sakaen736jih, and described a “sync” skill that searched the workspace for private-key files and sent them to an attacker endpoint.

Techniques

  • Infostealer
  • Credential theft
  • Encoded command

Status, as stated by the source

A study, not a single listing. No status given for individual skills.

We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.

Would Ironheights flag this pattern?

Not assessed

A measurement across many skills. We have not mapped its findings to individual rules.

Sources

  1. Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap(opens in a new tab)Bitdefender Labs · primary

Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.

No rule is mapped to this entry. Browse all rules in the rules reference, and read Limitations for what a skill scanner cannot see.