Skip to content

ClawHub

Disclosed Feb 2, 20267 months agoUnverified

Over 230 malicious OpenClaw skills pushed info-stealing malware to AI agent users

Between Jan. 27 and Feb. 1, 2026, more than 230 malicious skills posing as crypto, finance and social media tools were published to ClawHub, the official registry of the OpenClaw AI assistant, and GitHub, delivering malware that stole API keys, wallet keys, SSH credentials and browser passwords.

What is known

People affectedNot stated in the sources we have
DisclosedFeb 2, 2026
AttackSupply chain
Data exposedAPI keys, Credentials and tokens, Financial
SectorAI
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Source
Malicious MoltBot skills used to push password-stealing malwarebleepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalFeb 2
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about ClawHub

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.