{"id":10353,"date":"2026-02-03T10:03:46","date_gmt":"2026-02-03T10:03:46","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/03\/openclaw-ai-agent-skills-abused-by-threat-actors-to-deliver-malware\/"},"modified":"2026-02-03T10:03:46","modified_gmt":"2026-02-03T10:03:46","slug":"openclaw-ai-agent-skills-abused-by-threat-actors-to-deliver-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/03\/openclaw-ai-agent-skills-abused-by-threat-actors-to-deliver-malware\/","title":{"rendered":"OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware"},"content":{"rendered":"<p>    OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Hundreds of malicious skills designed to deliver trojans, <a href=\"https:\/\/cybersecuritynews.com\/infostealers-to-hijack-legitimate-business-infrastructure\/\" target=\"_blank\" rel=\"noreferrer noopener\">infostealers<\/a>, and backdoors disguised as legitimate automation tools.<\/p>\n<p>VirusTotal has uncovered a significant malware distribution campaign targeting OpenClaw, a rapidly growing personal AI agent ecosystem.<\/p>\n<p>OpenClaw, previously known as Clawdbot and briefly as Moltbot, is a self-hosted <a href=\"https:\/\/cybersecuritynews.com\/autonomous-ai-agents-are-becoming-the-new-os\/\" target=\"_blank\" rel=\"noreferrer noopener\">AI agent<\/a> that executes real system actions, including shell commands, file operations, and network requests.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-openclaw-skill-abuse-campaign\"><strong>OpenClaw Skill Abuse Campaign<\/strong><\/h2>\n<p>The platform extends functionality through skills, small packages built around SKILL.md files that users discover and install from ClawHub, the public marketplace for <a href=\"https:\/\/cybersecuritynews.com\/openclaw-ai-instances-exposed\/\" target=\"_blank\" rel=\"noreferrer noopener\">OpenClaw<\/a> extensions.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg1Srb_eHOJL8glBt4xpqYobCiNWxVaElpEZaGTVL2WN48IsAuMCt5pJaZcgZdU8LEvrSP1ZJldOJujfpCApze8PWw-TzKlIdtgHaVRAeN1u-1BifrT-4u1vjR4DUm9yQm9hmoRD3czYvJJTB-g-DxsDdOzUsrjSgHObj96TyY_X1VFEfg4-jtxVACByDM\/s1600\/Screenshot%25202026-02-03%2520103627%2520%25281%2529.webp?ssl=1\" alt=\"Users run untrusted code during setup(source : VirusTotal)\"><figcaption class=\"wp-element-caption\">Users run untrusted code during setup (source: VirusTotal)<\/figcaption><\/figure>\n<p>While this architecture enables powerful automation capabilities, it creates a dangerous attack surface.<\/p>\n<p>Skills run as third-party code with complete system access, often requiring users to paste commands into terminals, download binaries, or execute scripts during setup.<\/p>\n<p>Threat actors are exploiting this trust model to distribute <a href=\"https:\/\/cybersecuritynews.com\/new-stealthy-fileless-linux-malware-shadowhs\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> through seemingly helpful tools.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj-rBT0GzRpxmx2pddYiD-F9k0qhqi9mM8l1h24txFKQL9V33X5H9gAlYRCpL3sMouSnU2IZlMkVT9-5ARfV7AEP3fGB_AwaVnyytH1Ptny8fVQ9luwJ4yCtY8h4iOt6Jd0eJ3yIax9g0uE2ZCWPIRGv7uwp-Ag2rWL5Htp7QoweAyCiAvsz2fqRnujwUo\/s1600\/Screenshot%25202026-02-03%2520103846%2520%25281%2529.webp?ssl=1\" alt=\"A Mach-O binary flagged by 16 engines( source : VirusTotal)\"><figcaption class=\"wp-element-caption\">A Mach-O binary flagged by 16 engines (source: VirusTotal)<\/figcaption><\/figure>\n<p>VirusTotal Code Insight has analyzed over 3,016 OpenClaw skills, and hundreds of them exhibit malicious characteristics.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjow7nPFaJJWtnifafCO8z8Jx2Snk7BRXSJkcrduILpddl1I71TT29jlDY40nsSmxKlm_Che8X4nzIfPTv53n3MZLZoip02iwoINPKLjfo1tHAGY_mb8q4hWkH2v-pT5G4vL8pKfupopyXupztj6xlZVV2OhTvyp0G7B8-VKt0gEQZPWZNbrR3f9BgM7TI\/s1600\/Screenshot%25202026-02-03%2520103742%2520%25281%2529.webp?ssl=1\" alt=\"Base64-obfuscated macOS script( source : VirusTotal)\"><figcaption class=\"wp-element-caption\">Base64-obfuscated macOS script( source : VirusTotal)<\/figcaption><\/figure>\n<p>The analysis, powered by Gemini 3 Flash, examines security behaviors such as external code execution, sensitive data access, and unsafe network operations, rather than relying solely on traditional antivirus signatures.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj0HVsvh4m649kda8u_qVatG_Ztv6RKsVdsHZJ2Y4rATuxDymsvZLWnJ_FHEXUBOog0xCqe7mt69hfOlDIsio-wI6sbuvMxKymWM-uSgdX89Z27Iw4ZPRRyJid6CKaVJujzxufRrmA-bx5ztkvF62ovMHzl50EvK8r93qHqTsZqvAbUAaHGU0P3xkePvns\/s1600\/Screenshot%25202026-02-03%2520103911%2520%25281%2529.webp?ssl=1\" alt=\"Gemini 3 Pro flags it as AMOS infostealer( source : VirusTotal)\"><figcaption class=\"wp-element-caption\">Gemini 3 Pro flags it as AMOS infostealer( source : VirusTotal)<br \/><\/figcaption><\/figure>\n<p>Security researchers identified two distinct threat categories: skills that contain poor security practices, such as insecure APIs, hardcoded secrets, and unsafe command execution.<\/p>\n<p>Intentionally malicious skills designed for data exfiltration, remote control, and <a href=\"https:\/\/cybersecuritynews.com\/microsoft-office-0-day-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> installation.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-prolific-malware-publisher\"><strong>Prolific Malware Publisher<\/strong><\/h2>\n<p>A particularly concerning case involves ClawHub user \u201chightower6eu,\u201d who published 314 malicious skills covering crypto analytics, finance tracking, and social media analysis.<\/p>\n<p>Each skill instructs users to download and execute external code from untrusted sources during setup. One example, a \u201cYahoo Finance\u201d skill, appeared clean to traditional <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-weaponize-lnk-files-with-new-remcos\/\" target=\"_blank\" rel=\"noreferrer noopener\">antivirus engines<\/a>.<\/p>\n<p>However, VirusTotal Code Insight identified instructions directing Windows users to download a password-protected <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-using-multilingual-zip-file\/\" target=\"_blank\" rel=\"noreferrer noopener\">ZIP file<\/a> containing openclaw-agent.exe, which multiple vendors have detected as a packed trojan.<\/p>\n<p>For macOS users, the skill pointed to a Base64-obfuscated shell script on glot.io. That downloaded and executed a Mach-O binary identified as <a href=\"https:\/\/cybersecuritynews.com\/atomic-stealer-disguised-as-cracked-software\/\" target=\"_blank\" rel=\"noreferrer noopener\">Atomic Stealer (AMOS)<\/a>, an infostealer targeting passwords, browser credentials, and cryptocurrency wallets.<\/p>\n<p>Organizations and users should treat skill folders as trusted-code boundaries, implement sandboxed execution, and avoid skills that require shell commands or binary downloads.<\/p>\n<p>Marketplace operators should implement publish-time scanning to flag remote execution and obfuscated scripts.<\/p>\n<p>VirusTotal is <a href=\"https:\/\/blog.virustotal.com\/2026\/02\/from-automation-to-infection-how.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">exploring integration<\/a> with OpenClaw\u2019s publishing workflow to provide automated security analysis during skill submission.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/openclaw-ai-agent-skills-abused\/\">OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/openclaw-ai-agent-skills-abused\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware Hundreds of malicious skills designed to deliver trojans, infostealers, and backdoors disguised as legitimate automation tools. VirusTotal has uncovered a significant malware distribution campaign targeting OpenClaw, a rapidly growing personal AI agent ecosystem. OpenClaw, previously known as Clawdbot and briefly as Moltbot, is a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-10353","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10353"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10353"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10353\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}