What it did
About 40 trojanized skills from two accounts contained no malicious code, only a line saying a tool called OpenClawCLI must be installed first, with a link to a polished lookalike website that served the obfuscated install command. Because the skill files were clean, VirusTotal scanning of the skills did not catch them.
Skill names as reported
coding-agent696vgseo-optimizerc6ynbtavily-web-searchajsstelegramb4cyoutubeabrowserautomation-skill
Examples from the 40 skills the report lists.
Techniques
- Fake prerequisite
- Lookalike website
- Encoded command
- Scanner evasion
Status, as stated by the source
The report says the website was offline as of 9 February 2026 and that the skills remained in the openclaw/skills GitHub repository. It does not state the status of the skills on ClawHub.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Partly covered
Only the link to the undeclared website is flagged (IH-NET-001, medium, a review verdict). The install command lived on the website.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- Malicious ClawHub Skills Use External Websites to Hide in Plain Sight(opens in a new tab)OpenSourceMalware · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- Skills distributing an Atomic macOS Stealer variantTrend Micro · 23 February 2026Campaign
- copywritings and airbnb by StveenLiCommunity reports on GitHub (loganaden) · 10 February 2026Skill
- TradingView assistant skills delivering the cluw stealerPalo Alto Networks Unit 42 · 23 June 2026Skill
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-NET-002highPossible exfiltrationIH-EXEC-001criticalRemote content piped into an interpreterIH-CRED-001highAccess to a sensitive path