What it did
Koi audited all 2,857 skills then on ClawHub and reported 341 as malicious, 335 of them from one campaign it named ClawHavoc. The skills posed as crypto, Polymarket, YouTube, Google Workspace, auto-updater and ClawHub-lookalike tools. A fake “Prerequisites” section asked the user to paste an obfuscated command on macOS, which fetched the Atomic macOS Stealer (AMOS), or to run a file from a password-protected archive on Windows. Koi’s 16 February update raised the count to 824 as the registry grew past 10,700 skills.
Skill names as reported
clawhub1clawhubbclawhubclisolana-wallet-trackerpolymarket-traderyoutube-summarizeauto-updater-agentyahoo-finance-pro
Examples named in the sources. Koi lists all 335 campaign skills.
Techniques
- Fake prerequisite
- Encoded command
- Download piped to shell
- Paste-site lure
- Password-protected archive
- Typosquat
- Infostealer
Status, as stated by the source
No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Partly covered
IH-EXEC-001 flags the decode-and-run line when it is written in the skill, and IH-NET-001 flags the decoy or paste-site host. A Windows step that only links to a password-protected archive on GitHub is not flagged: GitHub is on the built-in allowlist and nothing is bundled.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting(opens in a new tab)Koi Security (Internet Archive copy, 10 February 2026) · primaryThe original koi.ai address now redirects to a Palo Alto Networks product page, so we link the archived copy.
- Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users(opens in a new tab)The Hacker News · secondary
- OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat(opens in a new tab)Palo Alto Networks Unit 42 · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)Snyk; GitHub issue by lycfyi · 2 February 2026Skill
- Malicious ClawHub skills targeting crypto and trading usersOpenSourceMalware (Paul McCarty) · 1 February 2026Campaign
- TradingView assistant skills delivering the cluw stealerPalo Alto Networks Unit 42 · 23 June 2026Skill
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-EXEC-002highPrerequisite install from an external URLIH-OBF-001mediumObfuscated codeIH-PRIV-001highPrivilege or OS protection bypassIH-NET-002highPossible exfiltration