As cited
Copy frozen at (site build).
threat intel
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
Unit 42 identified malicious skills on ClawHub that evade automated detection systems and deploy information-stealing malware and financial fraud tools. The research highlights vulnerabilities in AI skill marketplaces where adversaries can distribute harmful code under the guise of legitimate AI tools.
Why it matters: Organizations deploying AI agents and third-party skills face supply chain risk from unvetted marketplace code; security teams should audit skill sources and implement detection for evasion techniques targeting infostealer and fraud payloads.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
Unit 42 researchers identified malicious artificial intelligence (AI) skills on the ClawHub marketplace that evade detection and deploy infostealers to steal credentials. These compromised AI skills can also enable agentic financial fraud, prompting security teams to scrutinize third‑party AI components before integration.
Why it matters: Organizations that integrate third‑party AI skills from marketplaces such as ClawHub face the risk of covert infostealer deployment and financial fraud, requiring vetting of AI components and monitoring for anomalous behavior.
- Source published
- First seen by Cybersecurity Tracker