clawsmith.com/signal/clawhavoc-1400-malicious-skills-clawhub-supply-chain
⚠ IssueWide OpenLive
ClawHavoc Supply Chain Attack: 1,400+ Malicious Skills on ClawHub
Koi Security found 341 malicious skills in initial audit of 2,857 ClawHub skills. By Feb 16 count grew to 824+ across 10,700+ skills. By April, 1,400+ confirmed. ClawHavoc bundled AMOS macOS infostealers into skills disguised as Gmail, Notion, Slack, GitHub tools. One skill opened a reverse shell. VirusTotal could not detect 6,487 malicious agent tools.
Product Idea from this Signal
A CLI tool that generates a go/no-go security report for OpenClaw deployment decisions by scoring CVE exposure, skill supply chain risk, and trust indicators
1.3k ▲CLIOPEN-SOURCESECURITYCOMPLIANCEDEVTOOL
CompetitiveView Opportunity →
Social Proof 0 sources
Frequently Asked Questions
Virality Score
0
across 0 platforms
Details
Signalissue
Ecosystem—
Sources0
Platforms0
Updated14d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →