CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

More Malicious OpenClaw Skills Threaten AI Supply Chain

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 114

As cited

Copy frozen at (site build).

ai security

More Malicious OpenClaw Skills Threaten AI Supply Chain

OpenClaw removed five malicious packages from its ClawHub skills marketplace that had bypassed security controls and contained infostealers and other threats. The incident highlights gaps in the vetting process for AI skill repositories and the potential for supply chain compromise through seemingly legitimate add-ons.

Why it matters: Organizations using OpenClaw skills or deploying AI agents are at risk of installing compromised components; practitioners should review any ClawHub packages in use and strengthen vendor security assessment practices.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

More Malicious OpenClaw Skills Threaten AI Supply Chain

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

More Malicious OpenClaw Skills Threaten AI Supply Chain

OpenClaw removed five packages from its ClawHub skills marketplace after they bypassed security checks and contained infostealers and other threats. The incident highlights risks in the artificial intelligence supply chain. Malicious skills can compromise systems using the marketplace.

Why it matters: AI developers and organizations using OpenClaw or ClawHub face potential supply chain attacks via malicious skills.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary