CampaignStatus unknownCoverage: Partly coveredPrimary source

ClawHavoc

Reported by Koi Security on . Names, numbers, and dates are as the sources state them.

What it did

Koi audited all 2,857 skills then on ClawHub and reported 341 as malicious, 335 of them from one campaign it named ClawHavoc. The skills posed as crypto, Polymarket, YouTube, Google Workspace, auto-updater and ClawHub-lookalike tools. A fake “Prerequisites” section asked the user to paste an obfuscated command on macOS, which fetched the Atomic macOS Stealer (AMOS), or to run a file from a password-protected archive on Windows. Koi’s 16 February update raised the count to 824 as the registry grew past 10,700 skills.

Skill names as reported

  • clawhub1
  • clawhubb
  • clawhubcli
  • solana-wallet-tracker
  • polymarket-trader
  • youtube-summarize
  • auto-updater-agent
  • yahoo-finance-pro

Examples named in the sources. Koi lists all 335 campaign skills.

Techniques

  • Fake prerequisite
  • Encoded command
  • Download piped to shell
  • Paste-site lure
  • Password-protected archive
  • Typosquat
  • Infostealer

Status, as stated by the source

No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which.

We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.

Would Ironheights flag this pattern?

Partly covered

IH-EXEC-001 flags the decode-and-run line when it is written in the skill, and IH-NET-001 flags the decoy or paste-site host. A Windows step that only links to a password-protected archive on GitHub is not flagged: GitHub is on the built-in allowlist and nothing is bundled.

Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.

Sources

  1. ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting(opens in a new tab)Koi Security (Internet Archive copy, 10 February 2026) · primaryThe original koi.ai address now redirects to a Palo Alto Networks product page, so we link the archived copy.
  2. Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users(opens in a new tab)The Hacker News · secondary
  3. OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat(opens in a new tab)Palo Alto Networks Unit 42 · primary

Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.

Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.