Weak plugin checks allowed coordinated attacks on ClawHub, forcing OpenClaw to add stricter security scans. OpenClaw, an open-source AI agent project, has seen Weak plugin checks allowed coordinated attacks on ClawHub, forcing OpenClaw to add stricter security scans. OpenClaw, an open-source AI agent project, has seen

Security Firms Expose Hidden Backdoors in OpenClaw Plugins Targeting Users

2026/02/10 00:45
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Weak plugin checks allowed coordinated attacks on ClawHub, forcing OpenClaw to add stricter security scans.

OpenClaw, an open-source AI agent project, has seen rapid growth in recent weeks. Its official plugin marketplace, ClawHub, has followed the same path, drawing in many developers. However, the rising adoption has also drawn unwanted attention. Security firms now warn that ClawHub is being abused to spread malicious plugins.

Weak Plugin Reviews Leave OpenClaw’s ClawHub Exposed

Monitoring by SlowMist shows that ClawHub is becoming a new target for supply-chain attacks because the platform does not sufficiently verify uploads. Weak review controls have allowed unsafe plugins, referred to as “skills,” to enter the platform.

Several even carry hidden backdoors or deliver harmful content that puts both developers and users at risk. Following initial findings, SlowMist issued alerts to clients via its MistEye system and began tracking suspicious uploads.

A follow-up scan of ClawHub revealed the scale of the issue. According to a report from Koi Security, researchers found 341 malicious skills among 2,857 scanned. Most were designed to match known plugin-market poisoning campaigns seen in other ecosystems.

Many unsafe skills appeared legitimate at first glance, using trusted names and familiar descriptions.

Batch Attack Linked to Hundreds of Malicious Skills on ClawHub

SlowMist conducted a deeper review of the case and identified more than 400 indicators of malicious activity. Many of them pointed to the same few websites and servers. That repetition suggests the attacks were organized and planned.

Analysts described the campaign as batch-based, with attackers pushing many similar skills at once, all relying on shared infrastructure

Interestingly, the way these skills were spread also followed a pattern. Attackers used public file-hosting sites to store harmful code. The plugins first ran simple and slightly hidden instructions to avoid being flagged.

After that, they downloaded more dangerous code from external servers. This setup made it easy for attackers to update the malicious components without modifying the plugin itself.

Attackers also used misleading names to trick users. Many malicious skills were presented as crypto tools, finance helpers, or system utilities. Labels like “security check,” “automation helper,” or “update tool” made them seem safe and useful. 

SlowMist advised users to be careful before installing any ClawHub skill. Users should read the SKILL.md file closely before copying or running commands. Any plugin asking for system passwords, special permissions, or system changes should be treated with suspicion.

The security firm added that limiting permissions and manually reviewing code can help reduce risk. Security firms warn that stronger review processes and greater user awareness are now needed.

OpenClaw Moves to Tighten Plugin Security With VirusTotal Integration

OpenClaw recently announced a new partnership with VirusTotal to improve security across ClawHub. From now on, every skill published on ClawHub will go through automated security scanning powered by VirusTotal. This new layer of protection for developers and users will reduce risk as the platform grows.

Unlike traditional software, AI agents interpret language and take actions based on context. That makes them more flexible but also easier to misuse. OpenClaw said poorly secured agents can become a liability, especially when third-party skills gain access to tools and data.

Skills on ClawHub can manage finances, control devices, or automate tasks. Malicious skills could misuse that access to steal data, execute unwanted commands, or download harmful code. To address this risk, OpenClaw now scans skill packages before and after publication.

Under the new system, all active skills are rescanned daily. OpenClaw emphasised that this is a single security layer, with additional protections planned as the ecosystem expands.

The post Security Firms Expose Hidden Backdoors in OpenClaw Plugins Targeting Users appeared first on Live Bitcoin News.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Crypto Supercycle in 2025? DeepSeek Ranks the Best Altcoins to Buy Right Now

Crypto Supercycle in 2025? DeepSeek Ranks the Best Altcoins to Buy Right Now

The post Crypto Supercycle in 2025? DeepSeek Ranks the Best Altcoins to Buy Right Now appeared on BitcoinEthereumNews.com. Crypto Supercycle in 2025? DeepSeek Ranks the Best Altcoins to Buy Right Now Sign Up for Our Newsletter! For updates and exclusive offers enter your email. As a crypto writer, Krishi splits his time between decoding the chaos of the markets and writing about it in a way that doesn’t put you to sleep. He’s been at it for nearly two years in the crypto trenches. Yes, he regrets missing the magnificent rallies that came before that (who doesn’t!), but he’s more than ready to put his money where his words are. Before diving headfirst into crypto, Krishi spent over five years writing for some of the biggest names in tech, including TechRadar, Tom’s Guide, and PC Gaming, covering everything from gadgets and cybersecurity to gaming and software. When he’s not scouring and writing about the latest happenings in crypto, Krishi trades the forex market while keeping crypto in his long-term HODL plans. He’s a Bitcoin believer, though he never lets that bias creep into his writing. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/crypto-supercycle-2025-best-altcoins-to-buy-now-deepseek/
Share
BitcoinEthereumNews2025/09/18 01:45
Lido Posts 23% Revenue Drop in 2025, Plans LDO Buyback

Lido Posts 23% Revenue Drop in 2025, Plans LDO Buyback

Measured in ETH rather than dollars, Lido's total value locked fell from 9.63 million ETH to 8.81 million ETH.
Share
CryptoPotato2026/03/29 02:35
Ethena struggles as revenue falls 32% – Can demand save ENA at $0.089?

Ethena struggles as revenue falls 32% – Can demand save ENA at $0.089?

The post Ethena struggles as revenue falls 32% – Can demand save ENA at $0.089? appeared on BitcoinEthereumNews.com. Ethena’s [ENA] price now appears to be aligning
Share
BitcoinEthereumNews2026/03/29 02:15