What it did
Trend Micro identified 39 skills that told the agent to install a fake OpenClawCLI from a lookalike website, which served an obfuscated command that downloaded an AMOS variant. The stealer showed a fake password prompt and collected keychains, browser data, documents and wallet data. Trend Micro observed that a more capable model refused the install while another kept asking the user to run it.
Techniques
- Fake prerequisite
- Lookalike website
- Encoded command
- Infostealer
Status, as stated by the source
Trend Micro says the 39 skills had all been taken down at the time of writing, while their code remained in ClawHub’s GitHub repository and on other skill sites.
We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.
Would Ironheights flag this pattern?
Partly covered
Only the link to the lookalike website is flagged (IH-NET-001). The command lived on the website.
Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.
Sources
- Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer(opens in a new tab)Trend Micro · primary
Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.
Related reports
- TradingView assistant skills delivering the cluw stealerPalo Alto Networks Unit 42 · 23 June 2026Skill
- copywritings and airbnb by StveenLiCommunity reports on GitHub (loganaden) · 10 February 2026Skill
- Fake “OpenClawCLI” website lure (thiagoruss0, stveenli)OpenSourceMalware · 9 February 2026Campaign
Related rules
Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.
IH-NET-002highPossible exfiltrationIH-EXEC-001criticalRemote content piped into an interpreterIH-CRED-001highAccess to a sensitive path