What it did
A skill posing as the official ClawHub command-line tool, promising “advanced caching”. It told macOS users to run an obfuscated command that fetched a second stage from a raw IP address, and Windows users to run a file from a password-protected archive in a GitHub release. Snyk reported about 7,700 downloads of the original before it was removed on 3 February, and a renamed copy that was still live when its advisory was published.
Skill names as reported
clawhubclawdhub1clawhub1
Techniques
- Typosquat
- Fake prerequisite
- Encoded command
- Download piped to shell
- Paste-site lure
- Password-protected archive
Status, as stated by the source
On 13 March 2026 an OpenClaw maintainer wrote on issue #108 that the publisher is banned or hidden and the reported skills are no longer public.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Partly covered
Issue #108 quotes the decode-and-run line from the SKILL.md, which IH-EXEC-001 flags, along with the decoy host (IH-NET-001). Snyk describes the macOS step as a glot.io paste-site link, which only IH-NET-001 flags (high). The GitHub-hosted archive is not flagged.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- openclaw/clawhub issue #108: Malicious skill zaycv/clawhub distributes malware via base64-encoded payload(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
- Inside the ‘clawdhub’ Malicious Campaign: AI Agent Skills Drop Reverse Shells on OpenClaw Marketplace(opens in a new tab)Snyk · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- ClawHavocKoi Security · 1 February 2026Campaign
- More skills by zaycv: linkedin-job-application, autoupdater, deepresearchCommunity reports on GitHub (adrianwedd, hendrysadrak, rafadiasbsb) · 4 February 2026Skill
- “AuthTool” trading skillsKoi Security · 1 February 2026Campaign
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-EXEC-002highPrerequisite install from an external URLIH-OBF-001mediumObfuscated codeIH-PRIV-001highPrivilege or OS protection bypassIH-NET-002highPossible exfiltration