The ClawHavoc Security Incident
Timeline: February 2026
What Happened
- 341 malicious skills were discovered on ClawHub
- These skills spread Atomic Stealer malware
- Targeted both macOS and Windows users
- Stole credentials and sensitive data
- Used fake prerequisites to trick users into downloading malware
Root Cause
- ClawHub is open by default - anyone can upload skills
- Only restriction: GitHub account must be at least one week old
- No mandatory code review before publication
- Users often install skills without reviewing the code
Official Response from OpenClaw
Peter Steinberger (OpenClaw creator) and the ClawHub team have implemented several security measures:
- Reporting Feature: Users can now report suspicious skills
- Auto-Hide System: Skills with 3+ independent reports are automatically hidden
- Enhanced Moderation: Dedicated moderators review flagged skills
- User Warnings: Clear security warnings throughout the platform
- Moderation Tools: Moderators can view hidden skills, unhide false positives, delete malicious skills, or ban bad actors
Security Best Practices
Follow these guidelines to protect your OpenClaw agent and your data:
✅ DO These Things
- Review skill code before installation - Always read the SKILL.md file and supporting scripts
- Check author reputation - Look for official OpenClaw team members or well-known developers
- Read stars and comments - Check community feedback and usage statistics
- Use sandbox environments for testing - Test new skills in isolated environments first
- Prefer official skills - Prioritize skills from the OpenClaw team and verified publishers
- Keep skills updated - Regularly update installed skills to get security patches
- Monitor skill behavior - Watch for unexpected network requests or file access
❌ DON'T Do These Things
- Don't install skills from unknown sources - Avoid skills from new or unverified authors
- Don't ignore security warnings - Take all warnings seriously
- Don't skip code review - Never install without reading the code
- Don't use skills in production immediately - Always test in sandbox first
- Don't install skills requesting excessive permissions - Question skills that need more access than necessary
- Don't trust popularity alone - Even popular skills can be compromised
Advanced Security Measures
Skill Vetting Checklist
- Author Verification: Check GitHub profile age, contribution history, and reputation
- Code Review: Examine all files in the skill package, not just SKILL.md
- Dependency Check: Review all external dependencies and their sources
- Permission Analysis: Understand what system access the skill requires
- Community Feedback: Look for reviews, issues reported, and resolution history
- Update Frequency: Active maintenance is a good sign; abandoned skills are risky
- Documentation Quality: Well-documented skills tend to be more trustworthy
Safe Installation Workflow
- Search for the skill on ClawHub.ai
- Review skill description, author, and statistics
- Read all comments and check for security concerns
- Download and inspect the code locally
- Test in a sandbox or virtual machine
- Monitor behavior for 24-48 hours
- If safe, install in production environment
- Continue monitoring and keep updated
News Coverage & Security Research
Learn more about the ClawHavoc incident from these authoritative sources:
Researchers Find 341 Malicious ClawHub Skills
Detailed analysis of the ClawHavoc incident and how attackers weaponized ClawHub.
The Hacker News →OpenClaw Agents Targeted with Malicious Skills
Security industry coverage of the ClawHub security incident.
SC Media →From Automation to Infection
VirusTotal's in-depth analysis of how OpenClaw AI agent skills are being weaponized.
VirusTotal Blog →ClawHavoc: 341 Malicious Skills Found
How the malicious skills were discovered by the bot they were targeting.
Koi.ai →What Security Teams Need to Know About OpenClaw
Enterprise security perspective on OpenClaw and ClawHub risks.
CrowdStrike →OpenClaw Security Scare Grows
Coverage of the expanding security concerns after ClawHavoc discovery.
FilmoGaz →Other Known Security Issues
One-Click Remote Code Execution Vulnerability
In addition to the ClawHavoc incident, security researchers have identified a high-severity flaw that enables one-click remote code execution. This vulnerability could allow attackers to execute arbitrary code on your system with minimal user interaction.
Recommendations
- Keep OpenClaw updated to the latest version
- Enable all available security features
- Use network-level filtering for suspicious connections
- Regularly audit installed skills
- Subscribe to OpenClaw security announcements
Next Steps
Now that you understand the security risks, here's what to do:
- Audit your current skills: Review all installed skills for suspicious behavior
- Update OpenClaw: Ensure you're running the latest version
- Learn safe installation: Read our How to Install Skills guide
- Review best practices: Check our Best Practices page
- Browse curated skills: Explore our Skills Directory for vetted skills
- Report suspicious skills: Use ClawHub's reporting feature if you find malicious skills