Security Advisory: OpenClaw Official Plugin Center ClawHub Targeted in Large-Scale Malicious Skill Poisoning Campaign

By: theblockbeats.news|2026/02/09 14:00:52
0
Share
copy

BlockBeats News, February 9th, SlowMist issued a security advisory. Recently, the open-source artificial intelligence agent project OpenClaw unexpectedly gained popularity. Its official plugin center, ClawHub, is gradually becoming a new target for supply chain poisoning attacks, posing a potential security risk to developers and users. Monitoring shows that 341 malicious skills have been identified, which usually masquerade as cryptocurrency assets, security checks, or automation tools.

Attackers use the SKILL.md file as the entry point for execution instructions, hiding malicious commands through Base64 encoding and employing a two-stage loading mechanism to evade detection. The first stage retrieves the payload via curl, and the second stage deploys a sample named dyrtvwjfveyxjf23, deceiving users into entering their system password and stealing local documents and system information. Users are advised to review any command requiring execution, be cautious of prompts to obtain system privileges, and always prefer obtaining tools through official channels.

You may also like

WEEX AI Trading Hackathon 2026: How Top AI Strategies Dominated Real Markets

WEEX AI Trading Hackathon demonstrates that effective trading — whether powered by AI or human judgment — relies on core principles: understanding market structure, maintaining conviction, prioritizing quality over quantity, and managing risk intelligently.

WEEX Ai Trading Hackathon vs. Other AI Trading Competitions: Which Is Better for You?

The AI trading competition landscape offers distinct paths for growth. The WEEX AI Trading Hackathon differentiates itself through its focus on real-market execution and practical viability, positioning it as a key platform for aspiring quantitative traders and strategists.

Is AI Trading Replacing Humans? WEEX Hackathon Reveals the Future of Fintech

The WEEX AI Trading Hackathon reveals that the future of trading is not about AI replacing humans, but about collaboration. AI enhances trading capabilities, while human judgment, ethics, and strategic oversight remain essential.

Key Market Information Discrepancy on February 9th - A Must-See! | Alpha Morning Report

1. Top News: This Week's White House Crypto Meeting Focuses on Stablecoin Yield, Banking Reps to Attend for First Time 2. Token Unlock: $MOVE

"2.5 Dip" Real Reason: Wall Street Deleveraging Induced Overreaction

Bitcoin has now intricately woven itself into the financial capital markets in a very complex manner, and when cornered towards the opposite direction, the upward move will be more vertical than ever before.

Kyle's review of Hyperliquid sparks controversy, Solitude Bank officially opens, what are the overseas crypto communities talking about today?

What Was Top of Mind for Foreigners in the Last 24 Hours?

Popular coins

Latest Crypto News

Read more