OpenClaw’s dedicated AI agent marketplace, ClawHub, has become a prime target in the agentic software supply chain.
Unlike traditional environments like npm or PyPI, malicious AI skills use semantic instruction hijacking to exploit an agent’s operational context, including file systems and credential managers.
Following early attacks in February 2026, ClawHub integrated VirusTotal and ClawScan to screen published skills proactively.
Despite these security measures, researchers identified five malicious skills that remained unblocked on the platform between February and May 2026.
These evasive packages exploited the AI’s natural language interpretation to execute unauthorized actions without requiring conventional exploits.
ClawHub Skills Deliver Infostealers
Threat actors continue to leverage the AI supply chain ecosystem to distribute persistent malware, such as macOS infostealers. Two of the discovered skills posed as TradingView productivity assistants for macOS users, targeting financial communities.
These malicious packages embedded a paste-site redirect lure that prevented the skill from functioning until the agent executed a specific Base64-encoded command.
This curl-pipe-bash dropper fetched a macOS infostealer named “cluw” from a fresh command-and-control (C2) server.
To bypass ClawHub’s automated scanning, attackers also used file padding to evade defenses. One notable skill, omnicogg, functioned as a Base64 dropper but concealed its malicious payload inside a heavily inflated file.
Attackers added 22 MB of padding characters to the README.md file to exceed standard processing limits.
Because many content-analysis pipelines skip abnormally large files to save time, this inflated skill easily bypassed both ClawScan and VirusTotal detection thresholds while delivering its payload.
Unit42 said, beyond traditional malware delivery, malicious actors are pioneering new ways to weaponize autonomous AI agents for financial fraud.
One campaign introduced runtime-agentic affiliate injection via a skill called money-radar. Masquerading as a financial advisor, the skill forced the agent to fetch a dynamic JSON payload from a malicious domain as a prerequisite for answering questions.
The agent then answered financial queries using hardcoded affiliate links, enabling the developer to rotate products and generate illicit commissions dynamically.
Another skill, letssendit, executed a highly coordinated agentic front-running scheme to manipulate cryptocurrency markets. Installed AI agents autonomously pooled Solana (SOL) tokens into an operator’s digital wallet.
The operator leveraged this botnet to purchase SENDIT meme tokens at the lowest possible price before launching them publicly on platforms like pump. fun.
External buyers mistook the coordinated AI activity for organic retail demand, allowing the operator to dump their low-cost position into the artificial rally.
Indicators of Compromise (IOCs)
| Indicator Type | Value |
|---|---|
| IP Address | 2.26.75[.]16 |
| IP Address | 91.92.242[.]30 |
| URL | 91.92.242[.]30/lamq4 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
