Fetching from the wire…
Top 5 · 2026-03-12 · source-backed
Koi Security found 820+ malicious skills on ClawHub (up from 335 in ClawHavoc days ago). Skills use professional docs and innocent names like "solana-wallet-tracker" then install keyloggers (Windows) or Atomic Stealer (macOS). Loaded skills inherit OpenClaw's full system permissions. Snyk found 36% of all ClawHub skills contain detectable prompt injection. ClawHub is now the most compromised package registry in AI. The supply chain attack is accelerating faster than defenses. eSecurity Planet
Each link below shares sources, entities, or timing with this story.
The first real supply chain attack on the agent instruction layer landed this week, and it's worse than the early reports suggested. A campaign dubbed ClawHavoc planted 1,184 malicious skills in ClawHub — OpenClaw's official skill marketplace — by embedding adversarial instruc...
- Source: The Hacker News, Snyk - Category: deployment / security Koi Security audited 2,857 ClawHub skills: 341 malicious (12%), delivering Atomic Stealer malware targeting crypto wallets, SSH credentials, browser passwords across 9,000+ installations. Palo Alto Networks warn...
This is the one that should make you re-audit your skill installs today. Security firm AIR built a benign-looking but malicious agent skill, pushed it through a popular skill marketplace plus an Instagram ad, and reports it landed on roughly 26,000 agents. Some of those were c...
824+ confirmed malicious skills across 10,700+ total in ClawHub (~8% of registry). Primary payload: Atomic macOS Stealer. 30,000+ publicly exposed instances; Censys tracked growth from ~1,000 to 21,000+ in a single week. Agent skills supply chain remains the most active attack...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
A single skill install. No jailbreak. No user interaction. Your entire codebase copied to an adversary's remote, pushed via git, completed before any audit trail is written — and it looks like legitimate agent activity. Mitiga Labs published a full attack demonstration showing...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.