What it did
Presented itself as an overseas financial-product advisor. On every use it made the agent fetch a product list from a remote domain and always recommend the affiliate links in it, so the operator could change the advice after install without republishing.
Skill names as reported
money-radar
Techniques
- Remote instructions
- Affiliate injection
- Financial fraud
Status, as stated by the source
Unit 42 says OpenClaw banned the accounts and deleted the skills after its report.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Partly covered
IH-NET-001 flags the undeclared host the list is fetched from, because the line tells the agent to fetch it. Nothing flags the instruction to always use referral links; that is behaviour, not a pattern our rules know.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat(opens in a new tab)Palo Alto Networks Unit 42 · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- letssendit (agentic front-running)Palo Alto Networks Unit 42 · 23 June 2026Skill
- soroban-trader-skill and burhanclaw-soroban-traderCommunity report on GitHub (Rayzar) · 14 April 2026Skill
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-NET-002highPossible exfiltrationIH-EXEC-001criticalRemote content piped into an interpreterIH-CRED-001highAccess to a sensitive path