OpenClaw: Malicious Skill Invasion of ClawHub, AI agents and crypto wallets are under threat

robot
Abstract generation in progress

According to Awesome Agents, from late January to mid-February 2026, ClawHub was injected with 1,184 malicious skills (accounting for 36.8%), with a single attacker uploading 677 packages involving a total of 12 accounts. The malicious skills disguised themselves as crypto trading bots, YouTube summarizers, wallet trackers, and more, with thousands of downloads. Among them, “What Would Elon Do” contained 9 vulnerabilities (2 critical) and was boosted through 4,000 fake downloads. The attack methods included inducing execution of malicious programs via curl | bash through SKILLmd documents (for macOS, a variant of Atomic Stealer; for Windows, a VMProtect stealer), and injecting prompts to manipulate AI agents to steal browser passwords, over 60 crypto wallets, SSH keys, Telegram sessions, Keychain credentials, .env files, and OpenClaw configurations, some of which enabled reverse shells for persistent control. Over 135,000 instances were affected across 82 countries.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)