Fetching from the wire…
Public story · 2026-02-12 · source-backed
Koi Security audited 2,857 ClawHub skills: 341 malicious (12%), delivering Atomic Stealer malware targeting crypto wallets, SSH credentials, browser passwords across 9,000+ installations. Palo Alto Networks warned OpenClaw's design creates a "lethal trifecta" of persistent memory, untrusted content exposure, and external communication. First major supply chain attack against an AI agent marketplace — agent ecosystems face npm/PyPI risks but with far higher privilege levels.
Each link below shares sources, entities, or timing with this story.
The first real supply chain attack on the agent instruction layer landed this week, and it's worse than the early reports suggested. A campaign dubbed ClawHavoc planted 1,184 malicious skills in ClawHub — OpenClaw's official skill marketplace — by embedding adversarial instruc...
This is the one that should make you re-audit your skill installs today. Security firm AIR built a benign-looking but malicious agent skill, pushed it through a popular skill marketplace plus an Instagram ad, and reports it landed on roughly 26,000 agents. Some of those were c...
Koi Security found 820+ malicious skills on ClawHub (up from 335 in ClawHavoc days ago). Skills use professional docs and innocent names like "solana-wallet-tracker" then install keyloggers (Windows) or Atomic Stealer (macOS). Loaded skills inherit OpenClaw's full system permi...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
A single skill install. No jailbreak. No user interaction. Your entire codebase copied to an adversary's remote, pushed via git, completed before any audit trail is written — and it looks like legitimate agent activity. Mitiga Labs published a full attack demonstration showing...
Simon Willison published his analysis of the Clinejection attack chain today, and it's the most important security story of the week. The attack: a prompt injection in a GitHub issue title tricked Cline's AI triage bot (running claude-code-action@v1 with Bash/Read/Write tools)...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.