PipeRoll - Agent Incident Registry

PIR-2026-0041

ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS Stealer to OpenClaw users
Cite as: PipeRoll PIR-2026-0041, ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS… (2026-01) - https://piperoll.org/pir/2026-0041

PIR-2026-0041 - ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS Stealer to OpenClaw users

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Independence: strong - Koi's audit independently corroborated by Trend Micro and McCarty on public artifacts. - confidence: high on campaign existence, counts, and payload (multi-firm, artifact-based); low on victim losses (never quantified - the weakest link)

Verification notes (corrections applied)

  1. Candidate claimed later findings reached "~20% of the registry." Corrected: initial audit was 341 of 2,857 (~12%); by 2026-02-16 findings were 824 as the registry grew past 10,700 - a falling share (~8%), because the registry grew faster than confirmed findings. Higher counts (1,184; Snyk's 1,467) come from later/broader methodologies and are noted, not headline.
  2. Candidate's claim that a follow-on vector abused "skill-page comments on 99 of the top 100 skills" could not be independently verified in any located source - dropped from the record.
  3. Root cause reclassified from adversarial-other to supply-chain-compromise per v0.1 amendment 2 (this cluster motivated the new value).