A major security warning has hit the OpenClaw AI ecosystem. Blockchain security firm SlowMist found a large supply chain attack inside ClawHub. It is a platformA major security warning has hit the OpenClaw AI ecosystem. Blockchain security firm SlowMist found a large supply chain attack inside ClawHub. It is a platform

SlowMist Finds 341 Malicious Skills in OpenClaw Plugin Hub

2026/02/09 14:33
Okuma süresi: 3 dk

A major security warning has hit the OpenClaw AI ecosystem. Blockchain security firm SlowMist found a large supply chain attack inside ClawHub. It is a platform’s plugin marketplace. The issue surfaced after Koi Security scanned 2,857 skills and flagged 341 of them as malicious.

That means around 12% of the scanned plugins carried harmful code. The discovery raised concerns because OpenClaw has grown fast in recent months. Its open-source agent tools attracted many developers. It is also made the platform a bigger target for attackers.

Weak Reviews Let Malicious Skills Slip In

The attack worked because of weak review checks in the plugin store. Hackers uploaded skills that looked normal on the surface. However, the code inside them carried hidden instructions. SlowMist said many of these skills used a two-stage attack. First, the plugin contained obfuscated commands. These often appeared as normal setup or dependency steps. But the commands secretly decoded hidden scripts.

Then, the second stage downloaded the real malicious payload. The code pulled data from fixed domains or IP addresses. After that, it executed malware on the victim’s system. One example involved a skill called “X (Twitter) Trends.” It looked harmless and useful. However, it hid a Base64-encoded backdoor. The code could steal passwords, collect files and send them to a remote server.

Hundreds of Malicious Plugins Found

The scale of the attack surprised many analysts. Out of 2,857 scanned skills, 341 showed malicious behavior. Koi Security linked most of them to one large campaign. SlowMist also analyzed more than 400 indicators of compromise. The data showed organized batch uploads. Many plugins used the same domains and infrastructure.

The risks were serious for users running these skills. Some plugins requested shell access or file permissions. That gave the malware a chance to steal credentials, documents, and API keys. Some fake skills even mimicked crypto tools, YouTube utilities or automation helpers. These familiar names made them easier to install without suspicion.

Security Firms Urge Caution

Security researchers have already started cleanup efforts. SlowMist reported hundreds of suspicious items during early scans. Meanwhile, Koi Security released a free scanner for OpenClaw skills. Experts now warn users to avoid blindly running plugin commands. Many attacks started from simple setup steps inside skill files. Users should also avoid skills that ask for passwords or broad system access.

Developers are also urged to test plugins in isolated environments. Independent scans and official sources should be the first line of defense. This incident shows the risks inside fast growing AI ecosystems. Plugin marketplaces often move quickly, but security checks may lag behind. As AI agents gain more power, these platforms will need stronger review systems. Until then, users may need to treat every plugin like a potential threat.

The post SlowMist Finds 341 Malicious Skills in OpenClaw Plugin Hub appeared first on Coinfomania.

Piyasa Fırsatı
OpenClaw Logosu
OpenClaw Fiyatı(OPENCLAW)
$0.0002996
$0.0002996$0.0002996
-58.80%
USD
OpenClaw (OPENCLAW) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Nevada’s Legal Clash with Financial Prediction Platform Intensifies

Nevada’s Legal Clash with Financial Prediction Platform Intensifies

The post Nevada’s Legal Clash with Financial Prediction Platform Intensifies appeared on BitcoinEthereumNews.com. The legal conflict involving Kalshi, a significant
Paylaş
BitcoinEthereumNews2026/02/18 18:54
Nexstar Pulls ‘Jimmy Kimmel Live!’ From ABC Over Charlie Kirk Comments

Nexstar Pulls ‘Jimmy Kimmel Live!’ From ABC Over Charlie Kirk Comments

The post Nexstar Pulls ‘Jimmy Kimmel Live!’ From ABC Over Charlie Kirk Comments appeared on BitcoinEthereumNews.com. Topline “Jimmy Kimmel Live!” will be removed from local ABC stations owned by Nexstar “indefinitely,” according to a statement from the broadcasting giant, pulling the show after its host made comments about conservative activist Charlie Kirk, who was assassinated last week. Kimmel speaks at the 2022 Media Access Awards presented by Easterseals and broadcast on November 17, 2022. (Photo by 2022 Media Access Awards Presented By Easterseals/Getty Images for Easterseals) Getty Images for Easterseals Key Facts Nexstar said its “owned and partner television stations affiliated with the ABC Television Network will preempt” Kimmel’s show “for the foreseeable future beginning with tonight’s show.” This is a developing story. Check back for updates. Source: https://www.forbes.com/sites/antoniopequenoiv/2025/09/17/nexstar-will-pull-jimmy-kimmel-live-from-its-abc-stations-indefinitely-after-kimmels-comments-on-charlie-kirk/
Paylaş
BitcoinEthereumNews2025/09/18 07:59
XRP Price Faces Big Risk — But Smart Money Bets on 30% Rally

XRP Price Faces Big Risk — But Smart Money Bets on 30% Rally

The post XRP Price Faces Big Risk — But Smart Money Bets on 30% Rally appeared on BitcoinEthereumNews.com. XRP price gained nearly 7% over the past seven days.
Paylaş
BitcoinEthereumNews2026/02/18 19:13