What it did
A Google Workspace skill said an “openclaw-core” utility was required. Windows users were sent to a password-protected archive in a GitHub release and macOS users to a paste-site page with a command to copy into the terminal. openclaw-core does not exist.
Skill names as reported
google-qx4NET_NiNjA
Techniques
- Fake prerequisite
- Paste-site lure
- Password-protected archive
Status, as stated by the source
Snyk says the skill was flagged after warnings and that clones often reappear within hours. It does not say the skill was removed.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Partly covered
The paste-site link is flagged by IH-NET-001 (high, because paste sites are on the high-risk host list). The GitHub archive link is not flagged, and the command itself lived on the paste site.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware(opens in a new tab)Snyk · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)Snyk; GitHub issue by lycfyi · 2 February 2026Skill
- ClawHavocKoi Security · 1 February 2026Campaign
- TradingView assistant skills delivering the cluw stealerPalo Alto Networks Unit 42 · 23 June 2026Skill
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-NET-002highPossible exfiltrationIH-EXEC-001criticalRemote content piped into an interpreterIH-CRED-001highAccess to a sensitive path