SkillReported removedCoverage: Partly coveredPrimary source

copywritings and airbnb by StveenLi

Reported by Community reports on GitHub (loganaden) on . Names, numbers, and dates are as the sources state them.

What it did

The skills required a tool from a lookalike website. The website, not the skill, carried the obfuscated install commands for Windows and macOS, which pointed to the same raw IP address as the earlier campaigns.

Skill names as reported

  • copywritings
  • airbnb

Techniques

  • Fake prerequisite
  • Lookalike website
  • Encoded command

Status, as stated by the source

On 13 March 2026 an OpenClaw maintainer wrote that the publisher is banned and the reported skills are hidden.

We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.

Would Ironheights flag this pattern?

Partly covered

Only the link to the undeclared website is flagged (IH-NET-001, medium). The payload lives on the website, which Ironheights does not fetch.

Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.

Sources

  1. openclaw/clawhub issue #190: Malicious ai-skill (StveenLi/copywritings)(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
  2. openclaw/clawhub issue #191: Malicious ai-skill (StveenLi/airbnb)(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary

Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.

Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.