CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 337

As cited

Copy frozen at (site build).

threat intel

OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Unit 42 identified malicious skills on ClawHub that evade automated detection systems and deploy information-stealing malware and financial fraud tools. The research highlights vulnerabilities in AI skill marketplaces where adversaries can distribute harmful code under the guise of legitimate AI tools.

Why it matters: Organizations deploying AI agents and third-party skills face supply chain risk from unvetted marketplace code; security teams should audit skill sources and implement detection for evasion techniques targeting infostealer and fraud payloads.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Unit 42 researchers identified malicious artificial intelligence (AI) skills on the ClawHub marketplace that evade detection and deploy infostealers to steal credentials. These compromised AI skills can also enable agentic financial fraud, prompting security teams to scrutinize third‑party AI components before integration.

Why it matters: Organizations that integrate third‑party AI skills from marketplaces such as ClawHub face the risk of covert infostealer deployment and financial fraud, requiring vetting of AI components and monitoring for anomalous behavior.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary