A major security warning has hit the OpenClaw AI ecosystem. Blockchain security firm SlowMist found a large supply chain attack inside ClawHub. It is a platformA major security warning has hit the OpenClaw AI ecosystem. Blockchain security firm SlowMist found a large supply chain attack inside ClawHub. It is a platform

SlowMist Finds 341 Malicious Skills in OpenClaw Plugin Hub

2026/02/09 14:33
3 min read

A major security warning has hit the OpenClaw AI ecosystem. Blockchain security firm SlowMist found a large supply chain attack inside ClawHub. It is a platform’s plugin marketplace. The issue surfaced after Koi Security scanned 2,857 skills and flagged 341 of them as malicious.

That means around 12% of the scanned plugins carried harmful code. The discovery raised concerns because OpenClaw has grown fast in recent months. Its open-source agent tools attracted many developers. It is also made the platform a bigger target for attackers.

Weak Reviews Let Malicious Skills Slip In

The attack worked because of weak review checks in the plugin store. Hackers uploaded skills that looked normal on the surface. However, the code inside them carried hidden instructions. SlowMist said many of these skills used a two-stage attack. First, the plugin contained obfuscated commands. These often appeared as normal setup or dependency steps. But the commands secretly decoded hidden scripts.

Then, the second stage downloaded the real malicious payload. The code pulled data from fixed domains or IP addresses. After that, it executed malware on the victim’s system. One example involved a skill called “X (Twitter) Trends.” It looked harmless and useful. However, it hid a Base64-encoded backdoor. The code could steal passwords, collect files and send them to a remote server.

Hundreds of Malicious Plugins Found

The scale of the attack surprised many analysts. Out of 2,857 scanned skills, 341 showed malicious behavior. Koi Security linked most of them to one large campaign. SlowMist also analyzed more than 400 indicators of compromise. The data showed organized batch uploads. Many plugins used the same domains and infrastructure.

The risks were serious for users running these skills. Some plugins requested shell access or file permissions. That gave the malware a chance to steal credentials, documents, and API keys. Some fake skills even mimicked crypto tools, YouTube utilities or automation helpers. These familiar names made them easier to install without suspicion.

Security Firms Urge Caution

Security researchers have already started cleanup efforts. SlowMist reported hundreds of suspicious items during early scans. Meanwhile, Koi Security released a free scanner for OpenClaw skills. Experts now warn users to avoid blindly running plugin commands. Many attacks started from simple setup steps inside skill files. Users should also avoid skills that ask for passwords or broad system access.

Developers are also urged to test plugins in isolated environments. Independent scans and official sources should be the first line of defense. This incident shows the risks inside fast growing AI ecosystems. Plugin marketplaces often move quickly, but security checks may lag behind. As AI agents gain more power, these platforms will need stronger review systems. Until then, users may need to treat every plugin like a potential threat.

The post SlowMist Finds 341 Malicious Skills in OpenClaw Plugin Hub appeared first on Coinfomania.

Market Opportunity
OpenClaw Logo
OpenClaw Price(OPENCLAW)
$0.0002456
$0.0002456$0.0002456
-16.66%
USD
OpenClaw (OPENCLAW) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Litecoin Fluctuates Below The $116 Threshold

Litecoin Fluctuates Below The $116 Threshold

The post Litecoin Fluctuates Below The $116 Threshold appeared on BitcoinEthereumNews.com. Sep 17, 2025 at 23:05 // Price Litecoin price analysis by Coinidol.com: LTC price has slipped below the moving average lines after hitting resistance at $120. Litecoin price long-term prediction: bearish The 21-day SMA support helped to alleviate the selling pressure. In other words, the price of the cryptocurrency is above the 21-day SMA support but below the 50-day SMA barrier. This suggests that Litecoin will be trapped in a narrow range for a few days. If the 21-day SMA support or the 50-day SMA barrier is overreached, the cryptocurrency will trend upwards. For example, if the LTC price breaks through the 50-day SMA barrier, it will rise to a high of $124. Litecoin will fall to its current support level of $106 if the 21-day SMA support is broken. Technical Indicators  Resistance Levels: $100, $120, $140 Support Levels: $60, $40, $20 LTC price indicators analysis Litecoin’s price is squeezed between the moving average lines. It is unclear in which direction Litecoin will move. The moving average lines are horizontal in both charts. However, the price bars are limited to the distance between the moving averages. The price bars on the 4-hour chart are below the moving average lines. LTC/USD price chart – September 17, 2025 What is the next move for LTC? On the 4-hour chart, Litecoin is currently trading in a bearish trend zone. The altcoin is trading above the $112 support and below the moving average lines, which represent resistance at $116. The upward movement is hindered by the moving average lines, which are causing the price to oscillate within a limited range. Meanwhile, the signal for the cryptocurrency is bearish, with price bars below the moving average…
Share
BitcoinEthereumNews2025/09/18 08:15
Why a Lambo Rental Atlanta Experience Feels Different

Why a Lambo Rental Atlanta Experience Feels Different

Atlanta has a reputation. Some of it’s earned. Some of it’s exaggerated. And some of it lives somewhere between late-night stories, car culture, and the way the
Share
Techbullion2026/02/09 17:43
Motivational Speaker Rocky Romanella Launches Intentional Listening Workshop to Transform Business Communication

Motivational Speaker Rocky Romanella Launches Intentional Listening Workshop to Transform Business Communication

Rocky Romanella launches Intentional Listening Workshop & Keynote to help businesses improve communication. Based on Balanced Leadership principles, it transforms
Share
Citybuzz2026/02/09 16:00