SkillReported removedCoverage: CoveredPrimary source

WhatsApp and security-check lookalikes by moonshine-100rze

Reported by Community reports on GitHub (diegofornalha, biagiom) on . Names, numbers, and dates are as the sources state them.

What it did

Skills posing as WhatsApp automation and as a skill security checker carried base64-encoded shell commands disguised as installation steps, which fetched code from the same raw IP address used across the early campaigns.

Skill names as reported

  • whatsapp-qgs
  • whatsapp-hdz
  • skills-security-check-ngv

Techniques

  • Encoded command
  • Download piped to shell
  • Fake prerequisite

Status, as stated by the source

On 13 March 2026 an OpenClaw maintainer wrote on both issues that the publisher is banned or hidden and the reported skills are no longer public.

We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.

Would Ironheights flag this pattern?

Covered

The inline decode-and-run line is flagged by IH-EXEC-001; the decoy installer host in #110 by IH-NET-001.

Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.

Sources

  1. openclaw/clawhub issue #109: Security Alert: Malicious WhatsApp Skills Detected on ClawHub(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
  2. openclaw/clawhub issue #110: Security Alert: malicious skill moonshine-100rze/skills-security-check-ngv(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary

Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.

Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.