PipeRoll - Agent Incident Registry · about · contribute · data · notes · constitution · seismograph ↗

ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS Stealer to OpenClaw…

PipeRoll seal - registered recordPIR-2026-0041
Occurred
late 2026-01
Disclosed
2026-02-01 onward
Operator
individual
Blast radius
customers/third parties
Root cause
supply-chain-compromise
Failure locus
dependency
Severity
loss
Exploitation
in-wild-exploited
Direct loss (USD)
unknown
Telemetry
artifact-level witnessed
Confidence
high on campaign existence, counts, and…
Status
corroborated
Cite as: PipeRoll PIR-2026-0041, ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS… (2026-01) - https://piperoll.org/pir/2026-0041 markdown. Registered 2026-08-15 by Srinivas G.

PIR-2026-0041 - ClawHavoc: hundreds of malicious ClawHub skills deliver Atomic macOS Stealer to OpenClaw users

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Verification notes (corrections applied)

  1. Candidate claimed later findings reached "~20% of the registry." Corrected: initial audit was 341 of 2,857 (~12%); by 2026-02-16 findings were 824 as the registry grew past 10,700 - a falling share (~8%), because the registry grew faster than confirmed findings. Higher counts (1,184; Snyk's 1,467) come from later/broader methodologies and are noted, not headline.
  2. Candidate's claim that a follow-on vector abused "skill-page comments on 99 of the top 100 skills" could not be independently verified in any located source - dropped from the record.
  3. Root cause reclassified from adversarial-other to supply-chain-compromise per v0.1 amendment 2 (this cluster motivated the new value).

Corrections

See also - this event in the AI Incident Database: incident 1368.

More supply-chain-compromise records

← older: PIR-2026-0040 · registry · newer: PIR-2026-0042 →