ClawHavoc: 1,184 Malicious Skills Poison OpenClaw's ClawHub Registry
ClawHavoc supply chain attack planted 1,184-1,467 malicious skills in ClawHub. By mid-February registry grew to 10,700+ skills with 824+ malicious entries (20% of registry). Skills distributed infostealers, AMOS Stealer, and reverse shell backdoors.
Score Breakdown
Social Proof 4 sources
Existing Solutions 5 competitors
Google's VirusTotal now scans all skills published to ClawHub for malware.
Open-source CLI skill scanner released by Cisco for community skill vetting.
55-check automated audit and hardening tool for OpenClaw skill supply chain.
Proactive monitoring detecting ClawHavoc, AMOS stealer, CVE-2026-25253, and memory poisoning.
Crowdsource public security scanner for OpenClaw skills.
Gap Assessment
VirusTotal live in ClawHub; 5+ dedicated scanners (SecureClaw, clawvet, Cisco, openclaw-security-monitor, Clawned.io) already deployed.