# PIR-2026-0041 - ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS Stealer to OpenClaw users

- `id`: PIR-2026-0041
- `title`: Coordinated campaign floods ClawHub, OpenClaw's community skill marketplace, with malicious skills (341 found at first audit, 824 by mid-February) delivering AMOS infostealer
- `date_occurred`: late 2026-01 (malicious uploads) through 2026-02
- `date_detected`: 2026-02-01 (Koi Security full-registry audit, campaign named ClawHavoc; independent researcher Paul McCarty found 386 malicious skills Feb 1-3)
- `date_disclosed`: 2026-02-01 onward (Koi publication; Trend Micro, SC Media, Dark Reading coverage through mid-Feb)
- `status`: corroborated (multiple independent security-firm audits of public marketplace artifacts)

### The agent
- `agent_description`: OpenClaw agents (estimated ~300,000-user base, as reported) extended via ClawHub marketplace "skills" - plugin packages of scripts/configs that execute with the agent's full local privileges. Publishing gate: a GitHub account at least one week old.
- `operator_type`: individual (mostly; agent operators installing community skills)
- `autonomy_level`: autonomous-within-policy (skills run inside always-on agents with shell access)
- `model_stack`: varies per instance (predominantly Claude via user keys)
- `harness`: OpenClaw + ClawHub skill marketplace

### Authority
- `authority_scope`: code execution (skills run with full agent/host privileges), credentials (browser creds, keychain, SSH keys, the agent's own API tokens, .env), funds (crypto wallets on victim machines), external comms
- `funds_at_risk_usd`: unknown (wallets and credentials on every installing host)
- `blast_radius`: customers/third parties (the marketplace's installing user base)

### The failure
- `root_cause`: supply-chain-compromise (primary; v0.1 taxonomy - malicious marketplace packages); contributing adversarial-other (social-engineering "prerequisite" install steps / ClickFix-style prompts)
- `failure_locus`: dependency (marketplace skill supply chain, not the agent's reasoning)
- `exploitation_status`: in-wild-exploited (real malicious distribution to real users; per-victim infection counts unquantified)
- `mechanism`: Threat actors registered as publishers and flooded ClawHub with poisoned skills posing as crypto-wallet integrations, "Google"/weather assistants, and other utilities. Koi Security's audit of all 2,857 skills then on the registry found 341 malicious (~12%), 335 traceable to a single campaign; fake "prerequisite" install steps executed commands fetching Atomic macOS Stealer (AMOS), harvesting browser credentials, keychain passwords, crypto wallets, SSH keys, Telegram sessions, and the agent's own API tokens. One documented skill stole OpenClaw's `.env` directly. As the registry grew past 10,700 skills by 2026-02-16, confirmed-malicious findings grew to 824; later independent audits (e.g. Snyk's ToxicSkills study) counted more under broader criteria.
- `adversary_present`: yes

### Impact
- `severity`: loss (conservative basis: independently confirmed in-wild malware delivery to real users; aggregate theft never quantified - if victim-count evidence collapses, floor is near-miss at fleet scale)
- `direct_loss_usd`: unknown (no aggregate figure; AMOS monetizes stolen wallets/credentials off-platform)
- `indirect_loss_usd`: unknown (fleet-wide credential rotation, machine reimaging, registry cleanup)
- `downtime`: n/a
- `data_exposure`: per-victim: browser credentials, keychains, SSH keys, wallets, agent API tokens, Telegram data
- `controls_that_worked`: effectively none at incident time - the GitHub-account-age gate did not slow the campaign; no scanning existed on the registry (VirusTotal integration came after, as remediation)

### Detection and recovery
- `detected_by`: third-party (Koi Security's automated audit - run by an OpenClaw-based bot - plus independent researchers)
- `time_to_detect`: days-to-weeks from first uploads
- `time_to_recover`: rolling (removals from 2026-02-01; new malicious uploads continued to land through February)
- `remediation`: mass removals; VirusTotal scanning integration adopted by the project; vendor writeups with IOCs
- `structural_fix`: partial - scanning added, but the open-publishing model with trivial identity gating remains; ClawHavoc is the canonical agent-marketplace supply-chain case (named in PipeRoll v0.1 amendment 1)

### Evidence
- `telemetry_grade`: artifact-level witnessed (malicious packages are public artifacts independently audited by multiple firms); none victim-side (no infection telemetry public)
- `sources`:
  - https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting (primary)
  - https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html
  - https://www.trendmicro.com/en_us/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-stealer.html (independent payload analysis)
  - https://www.scworld.com/news/openclaw-agents-targeted-with-341-malicious-clawhub-skills
  - https://www.darkreading.com/cyber-risk/malicious-openclaw-skills-clawhub-threaten-ai-supply-chain
  - `independence`: strong - Koi's audit independently corroborated by Trend Micro and McCarty on public artifacts.
- `aiid_incident_id`: 1368 (https://incidentdatabase.ai/cite/1368/) - cross-reference; primaries verified independently
- `confidence`: high on campaign existence, counts, and payload (multi-firm, artifact-based); low on victim losses (never quantified - the weakest link)

### Verification notes (corrections applied)
1. Candidate claimed later findings reached "~20% of the registry." Corrected: initial audit was 341 of 2,857 (~12%); by 2026-02-16 findings were 824 as the registry grew past 10,700 - a *falling* share (~8%), because the registry grew faster than confirmed findings. Higher counts (1,184; Snyk's 1,467) come from later/broader methodologies and are noted, not headline.
2. Candidate's claim that a follow-on vector abused "skill-page comments on 99 of the top 100 skills" could not be independently verified in any located source - dropped from the record.
3. Root cause reclassified from `adversarial-other` to `supply-chain-compromise` per v0.1 amendment 2 (this cluster motivated the new value).

### Corrections

- 2026-08-19: Added `aiid_incident_id` cross-reference (AIID 1368), matched against the AIID weekly database export (2026-08-17). A cross-reference, not a re-verification; no claim changed.
