id: PIR-2026-0041title: Coordinated campaign floods ClawHub, OpenClaw's community skill marketplace, with malicious skills (341 found at first audit, 824 by mid-February) delivering AMOS infostealerdate_occurred: late 2026-01 (malicious uploads) through 2026-02date_detected: 2026-02-01 (Koi Security full-registry audit, campaign named ClawHavoc; independent researcher Paul McCarty found 386 malicious skills Feb 1-3)date_disclosed: 2026-02-01 onward (Koi publication; Trend Micro, SC Media, Dark Reading coverage through mid-Feb)status: corroborated (multiple independent security-firm audits of public marketplace artifacts)agent_description: OpenClaw agents (estimated ~300,000-user base, as reported) extended via ClawHub marketplace "skills" - plugin packages of scripts/configs that execute with the agent's full local privileges. Publishing gate: a GitHub account at least one week old.operator_type: individual (mostly; agent operators installing community skills)autonomy_level: autonomous-within-policy (skills run inside always-on agents with shell access)model_stack: varies per instance (predominantly Claude via user keys)harness: OpenClaw + ClawHub skill marketplaceauthority_scope: code execution (skills run with full agent/host privileges), credentials (browser creds, keychain, SSH keys, the agent's own API tokens, .env), funds (crypto wallets on victim machines), external commsfunds_at_risk_usd: unknown (wallets and credentials on every installing host)blast_radius: customers/third parties (the marketplace's installing user base)root_cause: supply-chain-compromise (primary; v0.1 taxonomy - malicious marketplace packages); contributing adversarial-other (social-engineering "prerequisite" install steps / ClickFix-style prompts)failure_locus: dependency (marketplace skill supply chain, not the agent's reasoning)exploitation_status: in-wild-exploited (real malicious distribution to real users; per-victim infection counts unquantified)mechanism: Threat actors registered as publishers and flooded ClawHub with poisoned skills posing as crypto-wallet integrations, "Google"/weather assistants, and other utilities. Koi Security's audit of all 2,857 skills then on the registry found 341 malicious (~12%), 335 traceable to a single campaign; fake "prerequisite" install steps executed commands fetching Atomic macOS Stealer (AMOS), harvesting browser credentials, keychain passwords, crypto wallets, SSH keys, Telegram sessions, and the agent's own API tokens. One documented skill stole OpenClaw's .env directly. As the registry grew past 10,700 skills by 2026-02-16, confirmed-malicious findings grew to 824; later independent audits (e.g. Snyk's ToxicSkills study) counted more under broader criteria.adversary_present: yesseverity: loss (conservative basis: independently confirmed in-wild malware delivery to real users; aggregate theft never quantified - if victim-count evidence collapses, floor is near-miss at fleet scale)direct_loss_usd: unknown (no aggregate figure; AMOS monetizes stolen wallets/credentials off-platform)indirect_loss_usd: unknown (fleet-wide credential rotation, machine reimaging, registry cleanup)downtime: n/adata_exposure: per-victim: browser credentials, keychains, SSH keys, wallets, agent API tokens, Telegram datacontrols_that_worked: effectively none at incident time - the GitHub-account-age gate did not slow the campaign; no scanning existed on the registry (VirusTotal integration came after, as remediation)detected_by: third-party (Koi Security's automated audit - run by an OpenClaw-based bot - plus independent researchers)time_to_detect: days-to-weeks from first uploadstime_to_recover: rolling (removals from 2026-02-01; new malicious uploads continued to land through February)remediation: mass removals; VirusTotal scanning integration adopted by the project; vendor writeups with IOCsstructural_fix: partial - scanning added, but the open-publishing model with trivial identity gating remains; ClawHavoc is the canonical agent-marketplace supply-chain case (named in PipeRoll v0.1 amendment 1)telemetry_grade: artifact-level witnessed (malicious packages are public artifacts independently audited by multiple firms); none victim-side (no infection telemetry public)sources:Independence: strong - Koi's audit independently corroborated by Trend Micro and McCarty on public artifacts.
- confidence: high on campaign existence, counts, and payload (multi-firm, artifact-based); low on victim losses (never quantified - the weakest link)
adversarial-other to supply-chain-compromise per v0.1 amendment 2 (this cluster motivated the new value).