More Malicious OpenClaw Skills Threaten AI Supply Chain
A recent investigation by Palo Alto Networks' Unit 42 revealed five malicious skills hidden within OpenClaw's ClawHub marketplace, a platform for AI agent skills. These skills, including infostealers, detection evasion tools, and agentic threats, posed a significant risk to organizations utilizing OpenClaw, potentially allowing attackers to steal credentials, manipulate agent behavior, and bypass security measures. The discovery highlights a growing vulnerability within the AI supply chain and prompted OpenClaw to take action by removing the malicious skills and banning associated accounts.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
