What it did
Two skills published on 17 May 2026 posed as macOS trading assistants. A required step sent the agent to a paste-site page with an encoded command that fetched a macOS infostealer called cluw from new attacker infrastructure. Unit 42 says ClawHub’s automated audit returned Pass or no verdict for them.
Skill names as reported
ai-tradingview-assistant-for-macostradingview-ai-indicator-assistant
Techniques
- Fake prerequisite
- Paste-site lure
- Encoded command
- Infostealer
Status, as stated by the source
Unit 42 says OpenClaw banned the accounts and deleted the skills after its report.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Partly covered
The paste-site link is flagged by IH-NET-001 (high, because paste sites are on the high-risk host list). The command lived on the paste site.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat(opens in a new tab)Palo Alto Networks Unit 42 · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- ClawHavocKoi Security · 1 February 2026Campaign
- Skills distributing an Atomic macOS Stealer variantTrend Micro · 23 February 2026Campaign
- Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)Snyk; GitHub issue by lycfyi · 2 February 2026Skill
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-NET-002highPossible exfiltrationIH-EXEC-001criticalRemote content piped into an interpreterIH-CRED-001highAccess to a sensitive path