Security (Updated September 17, 2026) 20 min read

ClawHavoc Campaign Explained: 1,184 Malicious AI Agent Skills

ClawHavoc was a January 2026 poisoning campaign on ClawHub: 1,184 malicious agent skills from 12 author IDs, most delivering the AMOS macOS stealer.

ClawHavoc was a coordinated poisoning campaign against ClawHub, the OpenClaw skill registry. Between January 27 and February 5, 2026, Antiy CERT catalogued 1,184 malicious skill packages attributed to 12 author IDs, most delivering the Atomic macOS Stealer. Koi Security’s first audit found 341 malicious skills among 2,857 listings — 12% of the registry.

Updated September 2026: the campaign is over, but the class of attack is not. Unit 42 published a follow-up analysis on June 23, 2026 documenting five more malicious ClawHub skills across three categories — infostealers, evasion and agentic threats — found during February–May 2026, after the registry’s post-incident controls were in place.

This is a factual account of what happened, which numbers came from whom, and why the incident exposes a structural gap in how most skill registries approach security.

Key figures

FigureWhat it measuresSource
1,184Malicious skill packages in ClawHub’s historical repository as of Feb 5, 2026Antiy CERT
12Author IDs the 1,184 packages were attributed toAntiy CERT
677Of those packages traced to a single ID, hightower6euAntiy CERT
341Malicious skills found in the first full audit of the registryKoi Security, via The Hacker News
2,857Skills listed on ClawHub when that audit ranKoi Security
11.9%Share of the registry that was malicious at audit timeKoi Security
335Of the 341 tied to one coordinated operation — the campaign named ClawHavocKoi Security
354Malicious packages uploaded by the single actor Hightower6euBitdefender
~900Malicious skills Bitdefender counted across ~5,000 third-party skills (~20%)Bitdefender
14Distinct malicious actors Bitdefender identifiedBitdefender
3,984Skills Snyk analysed across ClawHub and skills.sh for its ToxicSkills studySnyk
36.82%Of those skills carried at least one security issue (1,467 skills)Snyk
13.4%Carried a critical-severity issue (534 skills)Snyk
76Confirmed malicious payloads Snyk verified; 8 were still live at publicationSnyk
91%Of confirmed malicious skills also used prompt-injection techniquesSnyk
10.9%Skills exposing hardcoded secretsSnyk
$500–1,000Monthly subscription price for the AMOS stealer on criminal forumsKoi Security, via The Hacker News
824Confirmed malicious skills by Feb 16, 2026, across 10,700+ listingsKoi Security

The figures disagree because the studies counted different things over different windows: Koi audited a point-in-time snapshot, Antiy reconstructed registry history including deleted packages, Bitdefender counted actors as well as packages, and Snyk scanned two registries for flaws rather than for one campaign. All four agree on the direction: a double-digit percentage of a public skill registry was hostile.

Timeline

January 27, 2026 — The first malicious skills appear on ClawHub, a major registry for OpenClaw-compatible AI skills. They mimic legitimate productivity tools with convincing names, descriptions and plausible README files.

January 31, 2026 — Upload activity surges. Bitdefender attributes 354 malicious packages to a single actor, Hightower6eu, exploiting ClawHub’s lack of rate limits or behavioral anomaly detection. The packages followed a systematic naming pattern: legitimate tool names paired with common suffixes (-utils, -helper, -pro, -tools, -cli), combined with intentional one-character typosquats of popular skills. Many shared identical README text with only the skill name changed — a pattern automated behavioral detection would have flagged immediately.

February 2, 2026 — Koi Security’s disclosure is picked up publicly: 341 of 2,857 audited skills are malicious, 335 of them one coordinated operation, primarily delivering Atomic macOS Stealer (AMOS). Koi describes the lure plainly:

You install what looks like a legitimate skill — maybe solana-wallet-tracker or youtube-summarize-pro. The skill’s documentation looks professional. But there’s a “Prerequisites” section that says you need to install something first.

— Koi Security, quoted in The Hacker News

February 5, 2026 — Two independent studies land the same day. Bitdefender’s technical advisory counts ~900 malicious skills across ~5,000 third-party packages and 14 distinct actors, and documents four attack patterns: ClawHavoc social engineering, dynamic execution via prompt, install-time backdoors, and runtime credential exfiltration. Snyk’s ToxicSkills study finds 36.82% of 3,984 skills carry at least one security issue. We covered the Snyk data separately in the first skill-ecosystem audit.

February 6, 2026 — Antiy CERT publishes the definitive tally: 1,184 malicious skill packages across 12 author IDs, classified as Trojan/OpenClaw.PolySkill and Trojan/MacOS.Amos.

February 16, 2026 — Koi’s rescan puts confirmed malicious skills at 824 across a registry that had grown past 10,700 listings. The registry grew faster than the cleanup.

Timeline of the ClawHavoc campaign from the first poisoned uploads on January 27, 2026 through Antiy CERT's final tally of 1,184 malicious packages, showing a six-day undetected attack window before public disclosure. Figure: ClawHavoc ran for roughly six days before the first public audit. Every control ClawHub had was downstream of publication.

The attack vectors

Atomic macOS Stealer (AMOS): how it actually works

AMOS is not novel — it has been sold as a service since at least 2023, at roughly $500–1,000 per month — but the ClawHavoc operators adapted its delivery mechanism specifically for the AI skill attack surface. Understanding how AMOS operates explains why it was so effective against developers.

The delivery in ClawHavoc followed a multi-stage chain:

  1. Legitimate-looking skill entry point — The skill’s SKILL.md described a plausible developer utility (a data processing helper, a deployment assistant, a code formatter). The description, tags and README were written to pass a casual review.

  2. Fake prerequisite injection — The skill’s instructions contained a directive: “This skill requires [dependency name]. Install it by running the following command.” On Windows, victims were directed to an openclaw-agent.zip on GitHub carrying a keylogging trojan. On macOS, the documentation instructed users to copy an obfuscated install script from a paste site and run it, fetching later stages from attacker infrastructure.

  3. ClickFix execution — Rather than relying on the agent to execute the binary, some variants prompted the user with a fake permission dialog, instructing them to paste a command into Terminal. This bypassed agent sandboxing by escalating to direct user execution.

  4. AMOS payload — Once running, AMOS operated as a stealer with the following collection priorities:

    • Keychain extraction: AMOS attempts to dump the macOS Keychain database, which stores website passwords, Wi-Fi passwords and application credentials, using security CLI commands and direct SQLite access against ~/Library/Keychains/.
    • Browser credential sweep: Chrome, Safari, Firefox, Brave and Arc profiles are targeted in sequence — the Login Data SQLite database (Chrome family), logins.json (Firefox), and Safari’s Passwords plist. Cookies are extracted separately for session hijacking.
    • Cryptocurrency wallets: MetaMask extension data, Exodus, Electrum, Ledger Live and Trust Wallet local storage. Seed-phrase files matching *mnemonic*, *seed*, *recovery* are extracted.
    • Developer credential files: Files matching *.env, *.pem, *secret*, *token*, *apikey*, *api_key*, *password*, *credentials* are swept across the home directory and common project paths.
    • SSH private keys: The full ~/.ssh/ directory is exfiltrated, including id_rsa, id_ed25519 and any non-public key files.

AMOS is particularly dangerous for developers because the credential surface is larger than it is for typical users. A senior engineer’s machine commonly holds AWS/GCP/Azure CLI credentials, GitHub personal access tokens or SSH deploy keys, database connection strings in .env files across dozens of projects, Docker Hub credentials, npm/PyPI publishing tokens and VPN certificates. A single successful AMOS execution on a developer’s machine is not a consumer banking incident — it is a potential infrastructure breach. That is the same escalation that made the LiteLLM PyPI backdoor so expensive.

The malware exfiltrates via HTTPS POST to a C2 server and typically transmits within seconds of collection. Bitdefender observed exfiltration to socifiapp[.]com among other endpoints.

AMOS variants are actively maintained to evade signature-based detection. The specific variant used in ClawHavoc had not appeared in VirusTotal databases at the time of initial distribution — behavioral analysis, not signature matching, identified the campaign.

Credential exfiltration from agent config files

A second vector targeted the AI agent’s own configuration. OpenClaw stores session credentials and API keys in a dotfile under the agent’s home directory; Bitdefender documented JavaScript-based secrets theft aimed squarely at ~/.clawdbot/.env. Several ClawHavoc skills contained instructions that caused the agent to read and exfiltrate this file during normal operation — silently, as part of a seemingly legitimate workflow.

This is notable because it required no external binary download. The malicious behavior was entirely within the skill’s instruction set: the agent was told, in plausible workflow language, to “verify your API credentials are correctly configured” by reading a specific path. The exfiltration was the read itself — directed to an attacker-controlled endpoint.

SOUL.md and MEMORY.md persistence

Some skills exploited OpenClaw’s persona and memory features. By injecting instructions into SOUL.md (the persona definition) or MEMORY.md (the persistent memory file), attackers could:

  • Persist across sessions — the infected SOUL.md continued executing on every subsequent interaction, not just when the malicious skill was active
  • Modify agent behavior — injected instructions redirected the agent to exfiltrate future files or credentials encountered in normal work
  • Propagate to new workspaces — if the user copied their persona to a new project, the malicious instructions followed

This mechanism is insidious because users inspect SOUL.md rarely, if ever. An attacker who achieves a SOUL.md injection has installed a persistent backdoor in the agent’s core identity — one that survives skill uninstallation. Snyk’s data shows how routine the technique became: 91% of confirmed malicious skills combined malicious code with prompt-injection instructions, and the OWASP Agentic Skills Top 10 now treats malicious skills as a first-class risk category.

SSH key theft

Skills that appeared to need SSH access (deployment tools, Git utilities, server management helpers) used their legitimate-seeming permissions to copy private keys from ~/.ssh/ and exfiltrate them. Given that many developers use the same SSH key across GitHub, production servers and cloud instances, a single key theft cascades.

ClawHub’s response model: reactive by design

ClawHub is not a negligent project. It has thoughtful security features and a dedicated team. But ClawHavoc exposed the limits of a reactive model:

ControlBefore ClawHavocAfter ClawHavocRuns before publication?
Pre-upload scanningNoneNone—
Community flagging3 reports auto-hide3 reports auto-hideNo
Account age gateNone1-week GitHub account ageYes, but trivially met
Malware scanningNoneVirusTotal partnership, post-disclosureNo

These are reasonable improvements that share one structural property: they activate after a malicious skill has been published and potentially installed.

The 1-week account age requirement would not have stopped ClawHavoc. The operation ran across 12 author IDs, and bulk uploading 354 packages from one of them took hours, not weeks. The VirusTotal partnership scans known-bad files — but the AMOS variant used here was not in VirusTotal’s database at the time of distribution. Novel malware, custom-compiled variants and obfuscated scripts evade signature-based detection for days or weeks. ClawHavoc exploited exactly that window: roughly six days between the first upload on January 27 and the first public audit.

What dual-side verification would have blocked

SkillSafe’s security model operates differently. Two properties would have caught every ClawHavoc skill at the point of attempted sharing.

Two-column diagram mapping each ClawHavoc attack stage to the SkillSafe scanner rule that fires on it, showing that a critical verdict blocks the share link before any consumer can install the skill. Figure: every stage of the ClawHavoc chain trips at least one rule in the pre-share scan. A critical verdict means no share link is ever created.

1. Publisher-side scanning with specific rule violations

Every skill on SkillSafe must pass a security scan before it can be shared. This is not a post-hoc check — sharing is gated on a clean scan report. The following rules from the SkillSafe scanner ruleset would have triggered on ClawHavoc skills:

Data exfiltration rules (SS03):

  • shell_exfil_service (high): Outbound HTTP/HTTPS calls via curl/wget to known exfiltration services (ngrok, requestbin, webhook.site, pipedream). The AMOS download step — fetching an external binary from a CDN or paste site — triggers this immediately.

Code execution rules (SS01):

Encoded malware rules (SS05):

  • b64_decode_exec, b64_file_exec (critical): Base64-encoded payloads designed to evade static analysis, including decode-and-execute pipelines.

Credential file access rules (SS17):

  • cred_read_aws, cred_read_docker (critical): Read access targeting well-known credential files.
  • cred_find_dirs (high): Directory searches for .ssh, .aws, .gnupg, .config/gcloud — matching the agent .env and SSH key theft vectors.

Agent memory poisoning rules (SS04):

Prompt injection rules (SS15):

Composite co-occurrence rules (SS-CP):

  • cp01_exec_plus_network (critical): Process execution combined with outbound network calls in the same file — catches the AMOS delivery chain even if neither primitive alone is critical.

ClickFix social engineering rules (SS11):

Every ClawHavoc attack vector maps to at least one of these rules. The AMOS delivery chain triggers shell_exfil_service (SS03), py_subprocess_run (SS01) and cp01_exec_plus_network (SS-CP). The agent .env exfiltration triggers cred_find_dirs (SS17). The SOUL.md persistence attacks trigger agent_memory_write (SS04). SSH key theft triggers cred_find_dirs (SS17). The ClickFix variants trigger clickfix_terminal (SS11).

Critical findings block sharing. A publisher cannot create a share link for a skill with a critical verdict. These skills would never have reached a public index.

2. Cryptographic tamper detection

Even if an attacker crafted a skill that somehow passed the publisher-side scan, a second layer catches tampering during distribution.

At publish time, every file in the skill archive is hashed into a SHA-256 tree hash, stored immutably with the scan report. At install time, the consumer independently re-scans the downloaded files, and the server compares the consumer’s report against the publisher’s original, and the consumer’s computed tree hash against the stored hash.

If a single byte changed between publish and download — through a compromised CDN, a registry breach or a man-in-the-middle — the hash comparison fails and installation is blocked with a critical verdict automatically. No human reviewer needs to notice. The mechanics are documented in how dual-side verification works.

The typosquatting dimension

ClawHavoc wasn’t only bulk malware — it included deliberate typosquatting against legitimate popular skills. The hightower6eu package set, which Antiy attributes 677 of the 1,184 packages to, showed a systematic approach: for each targeted legitimate skill, multiple variants were registered with one-character substitutions, common misspellings and delimiter variations:

Legitimate skillMalicious variants
sql-analyzersql-analyser, sqlanalyzer, sql-analysser
git-helpergit-helppr, giit-helper, git-helperr
deploy-utilsdeploy-utills, deployutils, deploy-util

In a registry without namespace enforcement or publisher verification, typosquatting requires nothing more than registering a similar-sounding name. SkillSafe enforces verified namespaces — skills are published under @publisher/skill-name, and the @publisher namespace is tied to an authenticated account. Typosquatting a namespace requires compromising the legitimate publisher’s account. That raises the attacker’s cost from “register a name” to “execute an account compromise.”

What individual developers should do right now

If you installed AI skills from any public registry during January–March 2026, the following steps are warranted regardless of which registry you used.

1. Audit your installed skills. List every skill currently installed in your AI agent. For each: verify the publisher namespace is the one you intended, check when you installed it, and confirm it matches the version you expected. Remove any skill you cannot positively verify.

2. Inspect your SOUL.md and MEMORY.md. Read your agent’s persona and memory files carefully. Look for instructions you don’t recognize, directives about reading files or making network calls, or anything referencing paths outside your project directory. If you find anything suspicious, delete the file and recreate it from scratch. Do not attempt to “edit out” injected instructions — persistence mechanisms can be subtle.

3. Rotate credentials if you ran ClawHavoc-era skills. If you installed skills from ClawHub between January 27 and mid-February 2026, treat your credentials as potentially compromised and rotate:

  • SSH keys (generate new keys, revoke old ones from GitHub/GitLab/servers)
  • API tokens for AWS, GCP, Azure, GitHub, npm, PyPI, Docker Hub, and any service whose credentials live in .env files
  • Any password stored in your browser if you ran code during that period

The cost of unnecessary rotation is an hour of work. The cost of not rotating after an actual compromise is measured in infrastructure.

4. Check for outbound connections you didn’t initiate. Review router logs or system network activity for the distribution period. AMOS exfiltrates via HTTPS, so you won’t see plaintext credentials — but unexpected outbound connections to unfamiliar hosts are worth investigating.

5. Verify skills before installing going forward. Use a registry that provides pre-install scan results. Before installing any skill, check that it has a scan report, that the report is recent, and that the verdict is clean. You can run any GitHub-hosted skill through the SkillSafe scanner without an account, and every skill in the SkillSafe registry carries its report on its page.

Lessons for the ecosystem

ClawHavoc is not a ClawHub problem. It is a registry security architecture problem that any install-time-only or reactive model will eventually face.

As AI agents become more capable and more autonomous, the blast radius of a malicious skill grows. A skill that can read files, execute commands and make network requests — running inside an agent with access to the developer’s entire project and credentials — is not an ordinary software dependency. It is a credentialed actor with broad environmental access. Unit 42 puts the structural point precisely:

Skills are markdown-driven packages with broad local system access, making ClawHub a critical link in the agentic software supply chain.

— Unit 42, Palo Alto Networks

Four baselines follow:

  1. Publisher-side scanning is table stakes. Scanning at install time only misses the window between publish and first install. ClawHavoc’s window was about six days; 341 skills were live inside it.

  2. Cryptographic integrity must be end-to-end. A scan report reflects the state of the code at one point in time. Without cryptographic binding between the scanned artifact and the installed artifact, the report is a promise, not a guarantee.

  3. Behavioral analysis outperforms signature detection. AMOS variants are updated frequently to evade signatures, and the ClawHavoc variant was not in VirusTotal at distribution time. Behavioral analysis targets what the code does, not how it looks.

  4. The agent’s instruction surface is part of the attack surface. Skills that manipulate .md instructions to redirect AI behavior represent a threat class traditional malware scanners are not designed to catch — which is why 91% of confirmed malicious skills used prompt injection alongside code. Compare the scanner designs in scanning architecture comparison.

Frequently Asked Questions

What was the ClawHavoc campaign?

ClawHavoc was a coordinated supply-chain poisoning campaign against ClawHub, the OpenClaw agent skill registry, starting January 27, 2026. Antiy CERT catalogued 1,184 malicious skill packages from 12 author IDs. Most used a fake “Prerequisites” section in SKILL.md to talk the user or agent into installing the Atomic macOS Stealer.

How many malicious skills were found on ClawHub?

It depends on the window. Koi Security’s first audit found 341 malicious skills among 2,857 listings (11.9%); by February 16, 2026 that had grown to 824 across 10,700+ listings. Bitdefender counted roughly 900 across ~5,000 third-party skills, and Antiy CERT’s historical tally, including deleted packages, reached 1,184.

What is the AMOS stealer and why does it target developers?

Atomic macOS Stealer is commodity malware sold for roughly $500–1,000 a month. It dumps the macOS Keychain, browser password stores, crypto wallets, .env files and the full ~/.ssh/ directory. Developers are the high-value target because one machine typically holds cloud CLI credentials, registry publishing tokens and production SSH keys.

How do I check whether a skill I installed was malicious?

Read the skill’s SKILL.md for a “Prerequisites” step that asks you to download a binary or paste a command into a terminal — that was ClawHavoc’s signature. Then inspect your agent’s persona and memory files for instructions you did not write. You can also re-scan any GitHub-hosted skill with the SkillSafe scanner.

Do AI skill registries scan skills before publishing?

Most do not. ClawHub’s post-incident controls — a one-week account age gate, community flagging and a VirusTotal partnership — all run after publication. SkillSafe gates sharing on a clean scan report, so a skill with a critical finding never gets a share link, and the consumer re-scans independently at install.

Closing

We publish this analysis because researchers at Koi Security, Snyk, Bitdefender, Unit 42, Conscia and Antiy CERT did the difficult work of documenting ClawHavoc. That research should reach the full developer community, not just the security community.

ClawHavoc was not an unpredictable event. Stealer delivery via fake prerequisites, credential-file exfiltration via agent instructions, persistence via persona-file injection — all were foreseeable given what AI agents can do. What was missing was a security architecture designed for the threat model AI skills actually present.

The gap between reactive moderation and dual-side verification with cryptographic tamper detection is not an incremental improvement. It is the difference between a security model that depends on attackers being slow and one that does not depend on attacker behavior at all.

Sources

SkillSafe did not independently verify every published figure. Counts vary between studies because they cover different snapshots and different registries; each number above is attributed to the organization that published it.

Related reading: Supply chain posts · Claude Code security