logo

Security Advisory: OpenClaw Official Plugin Center ClawHub Targeted in Large-Scale Malicious Skill Poisoning Campaign

By: theblockbeats.news|2026/02/09 14:00:52
0
Share
copy

BlockBeats News, February 9th, SlowMist issued a security advisory. Recently, the open-source artificial intelligence agent project OpenClaw unexpectedly gained popularity. Its official plugin center, ClawHub, is gradually becoming a new target for supply chain poisoning attacks, posing a potential security risk to developers and users. Monitoring shows that 341 malicious skills have been identified, which usually masquerade as cryptocurrency assets, security checks, or automation tools.

Attackers use the SKILL.md file as the entry point for execution instructions, hiding malicious commands through Base64 encoding and employing a two-stage loading mechanism to evade detection. The first stage retrieves the payload via curl, and the second stage deploys a sample named dyrtvwjfveyxjf23, deceiving users into entering their system password and stealing local documents and system information. Users are advised to review any command requiring execution, be cautious of prompts to obtain system privileges, and always prefer obtaining tools through official channels.

You may also like

This Week's Key News Preview | The Federal Reserve Announces Interest Rate Decision; MegaETH Conducts TGE

Highlights of the week from April 27 to May 3.

Lower the expectations for the next bull market of BTC

Senior investors reveal high-level reduction in positions: In-depth analysis of six major risks including obstacles to sovereign entry, MicroStrategy's financing crisis, and the targeting of tokenized gold; expectations for the next bull market may cool down.

Morning News | Aave announces the establishment of a recovery fund; Michael Saylor releases Bitcoin Tracker information; Vietnam plans to launch a pilot project for crypto assets

Overview of Important Market Events on April 26

Crypto ETF Weekly | Last week, the net inflow for Bitcoin spot ETFs in the U.S. was $823 million; the net inflow for Ethereum spot ETFs in the U.S. was $155 million

GSR enters the cryptocurrency ETF market, launching its first multi-asset cryptocurrency ETF.

How to balance risk and return in DeFi yields?

Have these yields ever been reasonable? Have we ever received the compensation we deserve for the risks taken in DeFi, and where should the future spreads be set?

Tom Lee's Ethereum Thesis: Why the Man Who Called the Last Cycle Is Doubling Down on Bitmine

Tom Lee is emerging as one of Ethereum’s most influential supporters. From Fundstrat to Bitmine, his Ethereum thesis combines staking yield, treasury accumulation, and long-term network value. Here is why “Tom Lee Ethereum” has become one of crypto’s most watched narratives.

Popular coins

Latest Crypto News

Read more