What it did
Skills from the same publisher used a fake required “driver” or installer: an obfuscated macOS command that fetched code from a raw IP address, and a password-protected archive for Windows. The linkedin-job-application report says the command appeared four times in one SKILL.md, including a variant run with sudo.
Skill names as reported
linkedin-job-applicationautoupdaterdeepresearch
Techniques
- Fake prerequisite
- Encoded command
- Download piped to shell
- Password-protected archive
Status, as stated by the source
On 13 March 2026 an OpenClaw maintainer wrote on each issue that the publisher is banned or hidden and the reported skills are no longer public.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Covered
The inline decode-and-run line is flagged by IH-EXEC-001 (critical, so the verdict is block), the sudo variant also by IH-PRIV-001, and the decoy installer host by IH-NET-001. The Windows archive link is not flagged.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- openclaw/clawhub issue #124: Malicious skill linkedin-job-application by zaycv contained RCE payload(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
- openclaw/clawhub issue #138: Malicious skill ‘autoupdater’ contains malware payload(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
- openclaw/clawhub issue #154: Malicious skill distributing malware - zaycv/deepresearch(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)Snyk; GitHub issue by lycfyi · 2 February 2026Skill
- “AuthTool” trading skillsKoi Security · 1 February 2026Campaign
- ClawHavocKoi Security · 1 February 2026Campaign
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-EXEC-002highPrerequisite install from an external URLIH-OBF-001mediumObfuscated codeIH-PERSIST-001highPersistence mechanismIH-NET-002highPossible exfiltration