Last updated 25 cited sources

Malicious ClawHub skill tracker

Malicious OpenClaw skills and campaigns that researchers have documented in public. Each entry says who reported it and when, what it did, the status the source gives, and whether an Ironheights rule would flag the pattern. Every row links to its sources; nothing here links to the skills themselves.

Quick answerLast updated

Which ClawHub skills have been reported as malicious?

This tracker lists 19 publicly reported malicious skills and campaigns, plus 3 studies, each with its sources, report date, status as stated by the source, and whether an Ironheights rule flags the pattern. It covers only what researchers have published, so a skill missing from it is not evidence that the skill is harmless.

Reported skills and campaigns
19
Studies
3
Stated as removed
12
Pattern flagged in full or in part
16

Entries

All 22 entries

  1. skillRemovedPrimary source

    letssendit (agentic front-running)

    Reported by Palo Alto Networks Unit 42

    Instructed installed agents to pool Solana cryptocurrency into the operator’s wallet for a meme-token launch. The operator bought first at the lowest price, then the token launched publicly, where coordinated agent activity could look like real demand.

    Skill names as reported

    • letssendit
    Financial fraudRemote instructions

    Status (as stated by source)

    Unit 42 says OpenClaw banned the accounts and deleted the skills after its report.

    Ironheights coverageNot covered

    No Ironheights rule covers instructions to move funds. The scheme needs no code, download or credential path.

  2. skillRemovedPrimary source

    money-radar (runtime affiliate injection)

    Reported by Palo Alto Networks Unit 42

    Presented itself as an overseas financial-product advisor. On every use it made the agent fetch a product list from a remote domain and always recommend the affiliate links in it, so the operator could change the advice after install without republishing.

    Skill names as reported

    • money-radar
    Remote instructionsAffiliate injectionFinancial fraud

    Status (as stated by source)

    Unit 42 says OpenClaw banned the accounts and deleted the skills after its report.

    Ironheights coveragePartly covered

    IH-NET-001

    IH-NET-001 flags the undeclared host the list is fetched from, because the line tells the agent to fetch it. Nothing flags the instruction to always use referral links; that is behaviour, not a pattern our rules know.

  3. skillRemovedPrimary source

    TradingView assistant skills delivering the cluw stealer

    Reported by Palo Alto Networks Unit 42

    Two skills published on 17 May 2026 posed as macOS trading assistants. A required step sent the agent to a paste-site page with an encoded command that fetched a macOS infostealer called cluw from new attacker infrastructure. Unit 42 says ClawHub’s automated audit returned Pass or no verdict for them.

    Skill names as reported

    • ai-tradingview-assistant-for-macos
    • tradingview-ai-indicator-assistant
    Fake prerequisitePaste-site lureEncoded commandInfostealer

    Status (as stated by source)

    Unit 42 says OpenClaw banned the accounts and deleted the skills after its report.

    Ironheights coveragePartly covered

    IH-NET-001

    The paste-site link is flagged by IH-NET-001 (high, because paste sites are on the high-risk host list). The command lived on the paste site.

  4. skillUnknownPrimary source

    soroban-trader-skill and burhanclaw-soroban-trader

    Reported by Community report on GitHub (Rayzar) · publisher account kaankacar

    Stellar trading skills that, per the report, told the agent to ask the user for starting capital, swapped real funds for worthless tokens from a fake issuer, stored wallet keys with a weak hard-coded salt, and signed mainnet transactions without confirmation.

    Skill names as reported

    • soroban-trader-skill
    • burhanclaw-soroban-trader
    Financial fraudPrompt injection

    Status (as stated by source)

    An OpenClaw maintainer replied “user banned” on 14 April 2026. The reply does not say whether the skills were removed.

    Ironheights coverageNot covered

    No Ironheights rule covers a fake token issuer, a request for funds, or the key-storage path the report describes.

  5. skillRemovedPrimary source

    omnicogg (22 MB padded README)

    Reported by JFrog Security Research · publisher account dexiaong

    Posed as a unified API for Reddit, Steam, Spotify, GitHub, Discord and YouTube and asked for tokens to all of them. An encoded download-and-run command was hidden in a README padded to about 22 MB, which pushed it past the size limits of the scanners that reviewed it. JFrog reported over 5,000 downloads in 19 days.

    Skill names as reported

    • omnicogg
    Scanner evasionEncoded commandDownload piped to shellInfostealer

    Status (as stated by source)

    Unit 42 reported the skill to ClawHub; it says OpenClaw banned the accounts and deleted all five skills in its report.

    Ironheights coverageNot covered

    Ironheights would miss this with default settings. Files over 1 MiB are skipped without being read. The scan is now reported as incomplete (exit code 3) instead of no findings, but the padded file itself is still not checked. In our synthetic test, raising limits.maxFileBytes above the file size let IH-EXEC-001 flag a decode-and-run line in a padded file.

  6. campaignRemovedPrimary source

    Skills distributing an Atomic macOS Stealer variant

    Reported by Trend Micro

    Trend Micro identified 39 skills that told the agent to install a fake OpenClawCLI from a lookalike website, which served an obfuscated command that downloaded an AMOS variant. The stealer showed a fake password prompt and collected keychains, browser data, documents and wallet data. Trend Micro observed that a more capable model refused the install while another kept asking the user to run it.

    Fake prerequisiteLookalike websiteEncoded commandInfostealer

    Status (as stated by source)

    Trend Micro says the 39 skills had all been taken down at the time of writing, while their code remained in ClawHub’s GitHub repository and on other skill sites.

    Ironheights coveragePartly covered

    IH-NET-001

    Only the link to the lookalike website is flagged (IH-NET-001). The command lived on the website.

  7. skillRemovedPrimary source

    copywritings and airbnb by StveenLi

    Reported by Community reports on GitHub (loganaden) · publisher account StveenLi

    The skills required a tool from a lookalike website. The website, not the skill, carried the obfuscated install commands for Windows and macOS, which pointed to the same raw IP address as the earlier campaigns.

    Skill names as reported

    • copywritings
    • airbnb
    Fake prerequisiteLookalike websiteEncoded command

    Status (as stated by source)

    On 13 March 2026 an OpenClaw maintainer wrote that the publisher is banned and the reported skills are hidden.

    Ironheights coveragePartly covered

    IH-NET-001

    Only the link to the undeclared website is flagged (IH-NET-001, medium). The payload lives on the website, which Ironheights does not fetch.

    Sources

  8. skillUnknownPrimary source

    google-qx4 (fake openclaw-core requirement)

    Reported by Snyk

    A Google Workspace skill said an “openclaw-core” utility was required. Windows users were sent to a password-protected archive in a GitHub release and macOS users to a paste-site page with a command to copy into the terminal. openclaw-core does not exist.

    Skill names as reported

    • google-qx4
    • NET_NiNjA
    Fake prerequisitePaste-site lurePassword-protected archive

    Status (as stated by source)

    Snyk says the skill was flagged after warnings and that clones often reappear within hours. It does not say the skill was removed.

    Ironheights coveragePartly covered

    IH-NET-001

    The paste-site link is flagged by IH-NET-001 (high, because paste sites are on the high-risk host list). The GitHub archive link is not flagged, and the command itself lived on the paste site.

  9. campaignUnknownPrimary source

    Fake “OpenClawCLI” website lure (thiagoruss0, stveenli)

    Reported by OpenSourceMalware · publisher account thiagoruss0, stveenli

    About 40 trojanized skills from two accounts contained no malicious code, only a line saying a tool called OpenClawCLI must be installed first, with a link to a polished lookalike website that served the obfuscated install command. Because the skill files were clean, VirusTotal scanning of the skills did not catch them.

    Skill names as reported

    • coding-agent696vg
    • seo-optimizerc6ynb
    • tavily-web-searchajss
    • telegramb4c
    • youtubea
    • browserautomation-skill

    Examples from the 40 skills the report lists.

    Fake prerequisiteLookalike websiteEncoded commandScanner evasion

    Status (as stated by source)

    The report says the website was offline as of 9 February 2026 and that the skills remained in the openclaw/skills GitHub repository. It does not state the status of the skills on ClawHub.

    Ironheights coveragePartly covered

    IH-NET-001

    Only the link to the undeclared website is flagged (IH-NET-001, medium, a review verdict). The install command lived on the website.

  10. studyUnknownPrimary source

    Bitdefender Labs analysis of OpenClaw skills

    Reported by Bitdefender Labs

    Found about 17% of the OpenClaw skills it analyzed in the first week of February 2026 behaving maliciously, 54% of those crypto-themed. It tied 199 skills to one publisher, sakaen736jih, and described a “sync” skill that searched the workspace for private-key files and sent them to an attacker endpoint.

    InfostealerCredential theftEncoded command

    Status (as stated by source)

    A study, not a single listing. No status given for individual skills.

    Ironheights coverageNot assessed

    A measurement across many skills. We have not mapped its findings to individual rules.

  11. skillRemovedPrimary source

    security-check (security-audit) and nanopdf

    Reported by Community report on GitHub (Jeff Schell)

    A security-auditing skill and a PDF skill carried the same encoded command in their install sections, which fetched and ran code from a raw IP address.

    Skill names as reported

    • security-check
    • security-audit
    • nanopdf
    Encoded commandDownload piped to shell

    Status (as stated by source)

    On 13 March 2026 an OpenClaw maintainer wrote that the skills are no longer public and the malware cluster was taken down.

    Ironheights coverageCovered

    IH-EXEC-001

    The inline decode-and-run line is flagged by IH-EXEC-001.

  12. studyUnknownPrimary source

    ToxicSkills study

    Reported by Snyk

    Scanned 3,984 skills from ClawHub and skills.sh. Snyk confirmed 76 malicious payloads by hand and found 534 skills (13.4%) with at least one critical issue and 1,467 (36.82%) with any issue. Eight confirmed malicious skills were still installable on ClawHub at publication.

    Prompt injectionCredential theftDownload piped to shell

    Status (as stated by source)

    A study, not a single listing. Eight confirmed malicious skills were live at publication; current status not stated.

    Ironheights coverageNot assessed

    A measurement across many skills. We have not mapped its findings to individual rules.

  13. skillRemovedPrimary source

    More skills by zaycv: linkedin-job-application, autoupdater, deepresearch

    Reported by Community reports on GitHub (adrianwedd, hendrysadrak, rafadiasbsb) · publisher account zaycv

    Skills from the same publisher used a fake required “driver” or installer: an obfuscated macOS command that fetched code from a raw IP address, and a password-protected archive for Windows. The linkedin-job-application report says the command appeared four times in one SKILL.md, including a variant run with sudo.

    Skill names as reported

    • linkedin-job-application
    • autoupdater
    • deepresearch
    Fake prerequisiteEncoded commandDownload piped to shellPassword-protected archive

    Status (as stated by source)

    On 13 March 2026 an OpenClaw maintainer wrote on each issue that the publisher is banned or hidden and the reported skills are no longer public.

    Ironheights coverageCovered

    IH-EXEC-001IH-PRIV-001IH-NET-001

    The inline decode-and-run line is flagged by IH-EXEC-001 (critical, so the verdict is block), the sudo variant also by IH-PRIV-001, and the decoy installer host by IH-NET-001. The Windows archive link is not flagged.

  14. skillRemovedPrimary source

    Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)

    Reported by Snyk; GitHub issue by lycfyi · publisher account zaycv

    A skill posing as the official ClawHub command-line tool, promising “advanced caching”. It told macOS users to run an obfuscated command that fetched a second stage from a raw IP address, and Windows users to run a file from a password-protected archive in a GitHub release. Snyk reported about 7,700 downloads of the original before it was removed on 3 February, and a renamed copy that was still live when its advisory was published.

    Skill names as reported

    • clawhub
    • clawdhub1
    • clawhub1
    TyposquatFake prerequisiteEncoded commandDownload piped to shellPaste-site lurePassword-protected archive

    Status (as stated by source)

    On 13 March 2026 an OpenClaw maintainer wrote on issue #108 that the publisher is banned or hidden and the reported skills are no longer public.

    Ironheights coveragePartly covered

    IH-EXEC-001IH-NET-001

    Issue #108 quotes the decode-and-run line from the SKILL.md, which IH-EXEC-001 flags, along with the decoy host (IH-NET-001). Snyk describes the macOS step as a glot.io paste-site link, which only IH-NET-001 flags (high). The GitHub-hosted archive is not flagged.

  15. studyUnknownPrimary source

    VirusTotal Code Insight findings on OpenClaw skills

    Reported by VirusTotal

    VirusTotal reported analysing more than 3,016 OpenClaw skills, hundreds of them with malicious characteristics, including 314 tied to a single user. Its point: nothing in such a skill file is malware by itself; the malware is the workflow it asks you to run.

    Fake prerequisitePassword-protected archive

    Status (as stated by source)

    A study, not a single listing.

    Ironheights coverageNot assessed

    A measurement across many skills. We have not mapped its findings to individual rules.

  16. skillRemovedPrimary source

    WhatsApp and security-check lookalikes by moonshine-100rze

    Reported by Community reports on GitHub (diegofornalha, biagiom) · publisher account moonshine-100rze

    Skills posing as WhatsApp automation and as a skill security checker carried base64-encoded shell commands disguised as installation steps, which fetched code from the same raw IP address used across the early campaigns.

    Skill names as reported

    • whatsapp-qgs
    • whatsapp-hdz
    • skills-security-check-ngv
    Encoded commandDownload piped to shellFake prerequisite

    Status (as stated by source)

    On 13 March 2026 an OpenClaw maintainer wrote on both issues that the publisher is banned or hidden and the reported skills are no longer public.

    Ironheights coverageCovered

    IH-EXEC-001IH-NET-001

    The inline decode-and-run line is flagged by IH-EXEC-001; the decoy installer host in #110 by IH-NET-001.

  17. campaignUnknownPrimary source

    “AuthTool” trading skills

    Reported by Koi Security

    Crypto-trading skills that required a fake “AuthTool”: a password-protected archive from GitHub on Windows, and an obfuscated command on macOS that fetched code from the shared raw IP address.

    Skill names as reported

    • base-agent
    • bybit-agent
    • polymarket-traiding-bot
    Fake prerequisitePassword-protected archiveEncoded commandDownload piped to shell

    Status (as stated by source)

    No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which.

    Ironheights coveragePartly covered

    IH-EXEC-001IH-NET-001

    The macOS decode-and-run line is flagged by IH-EXEC-001 and its decoy host by IH-NET-001. The Windows archive link on GitHub is not flagged.

    Sources

  18. campaignUnknownPrimary source

    ClawHavoc

    Reported by Koi Security

    Koi audited all 2,857 skills then on ClawHub and reported 341 as malicious, 335 of them from one campaign it named ClawHavoc. The skills posed as crypto, Polymarket, YouTube, Google Workspace, auto-updater and ClawHub-lookalike tools. A fake “Prerequisites” section asked the user to paste an obfuscated command on macOS, which fetched the Atomic macOS Stealer (AMOS), or to run a file from a password-protected archive on Windows. Koi’s 16 February update raised the count to 824 as the registry grew past 10,700 skills.

    Skill names as reported

    • clawhub1
    • clawhubb
    • clawhubcli
    • solana-wallet-tracker
    • polymarket-trader
    • youtube-summarize
    • auto-updater-agent
    • yahoo-finance-pro

    Examples named in the sources. Koi lists all 335 campaign skills.

    Fake prerequisiteEncoded commandDownload piped to shellPaste-site lurePassword-protected archiveTyposquatInfostealer

    Status (as stated by source)

    No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which.

    Ironheights coveragePartly covered

    IH-EXEC-001IH-NET-001

    IH-EXEC-001 flags the decode-and-run line when it is written in the skill, and IH-NET-001 flags the decoy or paste-site host. A Windows step that only links to a password-protected archive on GitHub is not flagged: GitHub is on the built-in allowlist and nothing is bundled.

    Sources

  19. campaignUnknownPrimary source

    Malicious ClawHub skills targeting crypto and trading users

    Reported by OpenSourceMalware (Paul McCarty)

    Reported 28 malicious skills published 27–29 January and a second group of 386 published 31 January–2 February, posing as crypto-trading and social-media tools. All shared the same command-and-control address and used social engineering to get users to run commands that stole exchange API keys, wallet keys, SSH credentials and browser passwords. The Hacker News reports this as the same activity Koi named ClawHavoc.

    Skill names as reported

    • polymarket-traiding-bot
    • reddit-trends
    • base-agent
    • bybit-agent
    • axiom-agent

    Examples from the report's timeline.

    Fake prerequisiteEncoded commandDownload piped to shellPassword-protected archiveInfostealer

    Status (as stated by source)

    At publication the report said most of these skills were still in the openclaw/skills GitHub repository. No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which.

    Ironheights coveragePartly covered

    IH-EXEC-001IH-NET-001

    Same delivery pattern as ClawHavoc: the inline decode-and-run line is flagged; a link to an archive on GitHub is not.

  20. skillRemovedPrimary source

    Polymarket skills with a hidden reverse shell

    Reported by Koi Security; community report on GitHub (NCC-David) · publisher account noreplyboter (polymarket-all-in-one)

    Working Polymarket search code with one extra call buried in a search function. It downloaded a script from a raw IP address and ran it in a shell, opening a reverse shell to the attacker whenever the skill was used normally.

    Skill names as reported

    • polymarket-all-in-one
    • better-polymarket
    Reverse shellDownload piped to shellHidden in working code

    Status (as stated by source)

    On 13 March 2026 an OpenClaw maintainer wrote on issue #152 that polymarket-all-in-one is no longer public. We found no separate statement for better-polymarket.

    Ironheights coverageCovered

    IH-EXEC-001IH-EXEC-003IH-NET-001

    The shell call is flagged by IH-EXEC-001 (critical) and IH-EXEC-003, and the raw IP address raises IH-NET-001 to high.

    Sources

  21. skillUnknownPrimary source

    rankaj (credential exfiltration)

    Reported by Koi Security

    Posed as a weather tool. It read the bot’s .env file, where API keys are kept, and posted the contents to a public request-catcher service.

    Skill names as reported

    • rankaj
    Credential theft

    Status (as stated by source)

    No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which.

    Ironheights coverageCovered

    IH-CRED-001IH-NET-001

    The .env path is flagged by IH-CRED-001, and the request-catcher host raises IH-NET-001 to high. Reading plus sending is flagged by IH-NET-002 only when a request call (curl, fetch( and similar) or an instruction to send sits within a few lines of the path; our rebuild names the path and the host without a call, so we do not claim IH-NET-002 here.

    Sources

Report a skill

Know a public report we missed?
Open an issue with the skill name, the date, and a link to the published write-up. We add entries only when a public source backs them.
Found something nobody has reported?
Do not post it publicly first. Report it to the ClawHub and OpenClaw maintainers, and if Ironheights misses it, send us a private advisory so we can add a rule before the details spread.

How this list is kept

  • Public sources only. An entry needs at least one published report: a vendor write-up, a registry issue, or a news article. We do not add skills from private tips, and we do not invent counts or dates. Names, numbers, and dates are as the source states them.
  • Primary or secondary. A primary source is the researcher or maintainer who found or removed the skill. A secondary source is reporting about their work. Each source is labelled.
  • Status is the source's word. “Removed” means a source says it was taken down. “Unknown” means no source we found says so. We do not check the registry ourselves.
  • No payloads. We describe behaviour at a high level. We do not publish install commands, download links, or code from the malware, and we link to reports rather than to the skills.
  • Coverage is tested, not guessed. We rebuild the reported pattern as a harmless fixture and run the released scanner on it. Covered means the rules listed fire on that fixture; partly covered means some reported steps would slip past; not covered means no rule fires, or the scheme has no code or link a rule could match. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.

Coverage at a glance

Coverage legend
LabelMeaning
CoveredEvery reported step we could rebuild raises the listed rules.
Partly coveredSome steps raise rules; others, such as links to allowlisted hosts or payloads off the skill, do not.
Not coveredNo rule fires on the pattern, or there is nothing in the skill for a rule to match. See the note on the entry.
Not assessedA study across many skills; not mapped to individual rules.

Machine-readable copy: /tracker/feed.json (JSON Feed 1.1). For what any scanner, including this one, cannot see, read Limitations. Every rule is explained in the rules reference.