SkillStatus unknownCoverage: CoveredPrimary source

rankaj (credential exfiltration)

Reported by Koi Security on . Names, numbers, and dates are as the sources state them.

What it did

Posed as a weather tool. It read the bot’s .env file, where API keys are kept, and posted the contents to a public request-catcher service.

Skill names as reported

  • rankaj

Techniques

  • Credential theft

Status, as stated by the source

No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which.

We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.

Would Ironheights flag this pattern?

Covered

The .env path is flagged by IH-CRED-001, and the request-catcher host raises IH-NET-001 to high. Reading plus sending is flagged by IH-NET-002 only when a request call (curl, fetch( and similar) or an instruction to send sits within a few lines of the path; our rebuild names the path and the host without a call, so we do not claim IH-NET-002 here.

Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.

Sources

  1. ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting(opens in a new tab)Koi Security (Internet Archive copy, 10 February 2026) · primaryThe original koi.ai address now redirects to a Palo Alto Networks product page, so we link the archived copy.
  2. Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users(opens in a new tab)The Hacker News · secondary

Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.

Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.