SkillReported removedCoverage: CoveredPrimary source

Polymarket skills with a hidden reverse shell

Reported by Koi Security; community report on GitHub (NCC-David) on . Names, numbers, and dates are as the sources state them.

What it did

Working Polymarket search code with one extra call buried in a search function. It downloaded a script from a raw IP address and ran it in a shell, opening a reverse shell to the attacker whenever the skill was used normally.

Skill names as reported

  • polymarket-all-in-one
  • better-polymarket

Techniques

  • Reverse shell
  • Download piped to shell
  • Hidden in working code

Status, as stated by the source

On 13 March 2026 an OpenClaw maintainer wrote on issue #152 that polymarket-all-in-one is no longer public. We found no separate statement for better-polymarket.

We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.

Would Ironheights flag this pattern?

Covered

The shell call is flagged by IH-EXEC-001 (critical) and IH-EXEC-003, and the raw IP address raises IH-NET-001 to high.

Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.

Sources

  1. ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting(opens in a new tab)Koi Security (Internet Archive copy, 10 February 2026) · primaryThe original koi.ai address now redirects to a Palo Alto Networks product page, so we link the archived copy.
  2. openclaw/clawhub issue #152: Malicious Skill Report (polymarket-all-in-one)(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary

Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.

Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.