dotsagent.io
Language:English

ClawHavoc: hundreds of malicious ClawHub skills spread AMOS

Koi Security found 341 malicious skills among 2,857 on ClawHub, most delivering Atomic macOS Stealer. By 16 February 2026 the count had reached 824.

What happened

In early February 2026 Koi Security reviewed the 2,857 skills on ClawHub, OpenClaw's skill registry, and found 341 malicious ones. Of those, 335 delivered Atomic macOS Stealer (AMOS), and 29 were typosquats of clawhub. By 16 February the count had grown to 824 malicious skills out of more than 10,700.

VirusTotal linked 314 skills to a single user, hightower6eu, and described memory implants the skills wrote into SOUL.md and AGENTS.md. Since 7 February 2026, under a partnership with OpenClaw, VirusTotal scans every published skill and rescans them daily.

Why it worked

Skills run with the agent's own privileges, and OpenClaw does no local blocking of dangerous code at install time. Installing a skill means running a stranger's code, and a skill's text can also carry prompt injection into the agent's memory files.

What to do

  • Check each skill's ClawHub security audit status and VirusTotal verdict before installing it.
  • Set security.installPolicy, because there is no built-in blocking at install time.
  • Pin skill versions and review the changes before running openclaw skills update --all.
  • Check SOUL.md and AGENTS.md for instructions you did not write.
  • Run OpenClaw in a sandbox so a malicious skill cannot reach your credentials.

Vet skills, plugins and MCP serversSandbox code and tool execution

Work through the security checklist →

Sources

  1. koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-w
  2. trendmicro.com/en_gb/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-s

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026