What it did
Posed as a unified API for Reddit, Steam, Spotify, GitHub, Discord and YouTube and asked for tokens to all of them. An encoded download-and-run command was hidden in a README padded to about 22 MB, which pushed it past the size limits of the scanners that reviewed it. JFrog reported over 5,000 downloads in 19 days.
Skill names as reported
omnicogg
Techniques
- Scanner evasion
- Encoded command
- Download piped to shell
- Infostealer
Status, as stated by the source
Unit 42 reported the skill to ClawHub; it says OpenClaw banned the accounts and deleted all five skills in its report.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Not covered
Ironheights would miss this with default settings. Files over 1 MiB are skipped without being read. The scan is now reported as incomplete (exit code 3) instead of no findings, but the padded file itself is still not checked. In our synthetic test, raising limits.maxFileBytes above the file size let IH-EXEC-001 flag a decode-and-run line in a padded file.
Sources
- Anatomy of a Deception: Uncovering the ‘omnicogg’ Dropper in ClawHub(opens in a new tab)JFrog Security Research · primary
- OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat(opens in a new tab)Palo Alto Networks Unit 42 · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- ClawHavocKoi Security · 1 February 2026Campaign
- Malicious ClawHub skills targeting crypto and trading usersOpenSourceMalware (Paul McCarty) · 1 February 2026Campaign
- TradingView assistant skills delivering the cluw stealerPalo Alto Networks Unit 42 · 23 June 2026Skill
Related rules
No rule is mapped to this entry. Browse all rules in the rules reference, and read Limitations for what a skill scanner cannot see.