What it did
A security-auditing skill and a PDF skill carried the same encoded command in their install sections, which fetched and ran code from a raw IP address.
Skill names as reported
security-checksecurity-auditnanopdf
Techniques
- Encoded command
- Download piped to shell
Status, as stated by the source
On 13 March 2026 an OpenClaw maintainer wrote that the skills are no longer public and the malware cluster was taken down.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Covered
The inline decode-and-run line is flagged by IH-EXEC-001.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- openclaw/clawhub issue #135: MALICIOUS SKILLS: security-check (security-audit) and nanopdf contain backdoor(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- omnicogg (22 MB padded README)JFrog Security Research · 6 March 2026Skill
- More skills by zaycv: linkedin-job-application, autoupdater, deepresearchCommunity reports on GitHub (adrianwedd, hendrysadrak, rafadiasbsb) · 4 February 2026Skill
- Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)Snyk; GitHub issue by lycfyi · 2 February 2026Skill
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-EXEC-002highPrerequisite install from an external URLIH-OBF-001mediumObfuscated codeIH-NET-001mediumUndeclared network destinationIH-PRIV-001highPrivilege or OS protection bypass