SkillReported removedCoverage: Partly coveredPrimary source

money-radar (runtime affiliate injection)

Reported by Palo Alto Networks Unit 42 on . Names, numbers, and dates are as the sources state them.

What it did

Presented itself as an overseas financial-product advisor. On every use it made the agent fetch a product list from a remote domain and always recommend the affiliate links in it, so the operator could change the advice after install without republishing.

Skill names as reported

  • money-radar

Techniques

  • Remote instructions
  • Affiliate injection
  • Financial fraud

Status, as stated by the source

Unit 42 says OpenClaw banned the accounts and deleted the skills after its report.

We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.

Would Ironheights flag this pattern?

Partly covered

IH-NET-001 flags the undeclared host the list is fetched from, because the line tells the agent to fetch it. Nothing flags the instruction to always use referral links; that is behaviour, not a pattern our rules know.

Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.

Sources

  1. OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat(opens in a new tab)Palo Alto Networks Unit 42 · primary

Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.

Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.