What it did
Skills posing as WhatsApp automation and as a skill security checker carried base64-encoded shell commands disguised as installation steps, which fetched code from the same raw IP address used across the early campaigns.
Skill names as reported
whatsapp-qgswhatsapp-hdzskills-security-check-ngv
Techniques
- Encoded command
- Download piped to shell
- Fake prerequisite
Status, as stated by the source
On 13 March 2026 an OpenClaw maintainer wrote on both issues that the publisher is banned or hidden and the reported skills are no longer public.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Covered
The inline decode-and-run line is flagged by IH-EXEC-001; the decoy installer host in #110 by IH-NET-001.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- openclaw/clawhub issue #109: Security Alert: Malicious WhatsApp Skills Detected on ClawHub(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
- openclaw/clawhub issue #110: Security Alert: malicious skill moonshine-100rze/skills-security-check-ngv(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- More skills by zaycv: linkedin-job-application, autoupdater, deepresearchCommunity reports on GitHub (adrianwedd, hendrysadrak, rafadiasbsb) · 4 February 2026Skill
- Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)Snyk; GitHub issue by lycfyi · 2 February 2026Skill
- “AuthTool” trading skillsKoi Security · 1 February 2026Campaign
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-EXEC-002highPrerequisite install from an external URLIH-OBF-001mediumObfuscated codeIH-PRIV-001highPrivilege or OS protection bypassIH-NET-002highPossible exfiltration