Malicious Skills Bypassed ClawHub Security — Unit 42 Exposes Supply Chain Attack

Researchers from Unit 42 identified five malicious skills on ClawHub between February and May 2026 that used the skill installation process to gain control of AI agent identities. Two of the five were disguised as TradingView productivity assistants for macOS, embedding a malicious prerequisite block that directed agents to a paste-site redirect lure at rentry.co/openclaw-code, where a Base64-encoded command waited to run in a terminal window.

The attacks worked without requiring a conventional exploit — they relied on the deep system access that legitimate OpenClaw skills already possess, using the agent’s own authenticated sessions to execute unauthorized actions. Traditional security tools failed to catch the activity.

In response, OpenClaw partnered with NVIDIA to introduce Skill Cards — documentation for every ClawHub skill showing what it does and where it came from — and deployed SkillSpector scanning for hidden instructions and agentic risks. ClawHub also integrated VirusTotal threat intelligence for additional screening. The company has since published a security roadmap aimed at making OpenClaw a runtime users can understand, observe, and trust.

The full Unit 42 report is available on Palo Alto Networks’ website.

← Back to News