What it did
Crypto-trading skills that required a fake “AuthTool”: a password-protected archive from GitHub on Windows, and an obfuscated command on macOS that fetched code from the shared raw IP address.
Skill names as reported
base-agentbybit-agentpolymarket-traiding-bot
Techniques
- Fake prerequisite
- Password-protected archive
- Encoded command
- Download piped to shell
Status, as stated by the source
No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Partly covered
The macOS decode-and-run line is flagged by IH-EXEC-001 and its decoy host by IH-NET-001. The Windows archive link on GitHub is not flagged.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting(opens in a new tab)Koi Security (Internet Archive copy, 10 February 2026) · primaryThe original koi.ai address now redirects to a Palo Alto Networks product page, so we link the archived copy.
- Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap(opens in a new tab)Bitdefender Labs · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- More skills by zaycv: linkedin-job-application, autoupdater, deepresearchCommunity reports on GitHub (adrianwedd, hendrysadrak, rafadiasbsb) · 4 February 2026Skill
- Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)Snyk; GitHub issue by lycfyi · 2 February 2026Skill
- ClawHavocKoi Security · 1 February 2026Campaign
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-EXEC-002highPrerequisite install from an external URLIH-OBF-001mediumObfuscated codeIH-PRIV-001highPrivilege or OS protection bypassIH-NET-002highPossible exfiltration