ClawHavoc Security Incident - What You Need to Know
Security researchers discovered 341 malicious skills on ClawHub containing Atomic Stealer malware. All affected skills were removed within 24 hours.
Key Points:
- 341 malicious skills identified and removed
- Atomic Stealer malware targeted credentials and crypto wallets
- Enhanced security measures now in place
- Users advised to follow security best practices
- Full incident timeline and affected skills list available
What Happened
In early February 2026, security researchers discovered a coordinated attack where malicious actors uploaded skills containing Atomic Stealer malware to ClawHub. The malware was designed to steal:
- User credentials and passwords
- Cryptocurrency wallet data
- Sensitive personal information
Attack Method
The malicious skills used fake prerequisites to trick users into downloading and executing malware. The skills appeared legitimate but contained hidden malicious code targeting both macOS and Windows systems.
OpenClaw Team Response
The OpenClaw team, led by Peter Steinberger, acted swiftly:
- All 341 malicious skills removed within 24 hours
- Security audit of remaining skills conducted
- Enhanced security measures implemented immediately
- Community notified through all channels