Hundreds of malicious skills found in OpenClaw's marketplace
Koi Security said most of the packages were crypto-themed lures delivering infostealers to the agent's host machine.
By The Agentic Times ·
Several hundred malicious skills were discovered on ClawHub, the community marketplace for the OpenClaw personal AI agent, in early February 2026. Koi Security, which reported the campaign, said the skills were mostly disguised as cryptocurrency trading tools and utilities, and installed information-stealing malware on the machines running the agent.
OpenClaw skills are folders of instructions and scripts that extend what an agent can do. Because the agent runs with its owner's permissions and can execute commands, a skill that asks the agent to run a setup script is effectively an installer. Koi found that many of the malicious skills instructed the agent to download and run a payload, and that the packages had been published in bulk over about a week.
The payloads harvested browser credentials, cryptocurrency wallets and session tokens. Koi named the campaign ClawHavoc and said it was the largest cluster of malicious packages it had seen in an agent ecosystem.
ClawHub removed the listings after disclosure and said it was adding automated scanning and publisher verification. The OpenClaw maintainers advised users to review skills before installing them and to run agents in a container rather than directly on a personal machine.
The episode followed the Moltbook database exposure by only days and cemented OpenClaw's position as the first consumer agent ecosystem to attract sustained criminal attention. Security researchers compared the marketplace problem to the early years of browser extension stores, where trust was assumed until it was widely abused.
Sources
- koi.aihttps://www.koi.ai/blog/clawhavoc-341-malicious-clawhub-skills-koi-research
