ClawHub
Disclosed Feb 2, 20267 months agoUnverified
Over 230 malicious OpenClaw skills pushed info-stealing malware to AI agent users
Between Jan. 27 and Feb. 1, 2026, more than 230 malicious skills posing as crypto, finance and social media tools were published to ClawHub, the official registry of the OpenClaw AI assistant, and GitHub, delivering malware that stole API keys, wallet keys, SSH credentials and browser passwords.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Feb 2, 2026 |
| Attack | Supply chain |
| Data exposed | API keys, Credentials and tokens, Financial |
| Sector | AI |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Malicious MoltBot skills used to push password-stealing malwarebleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Feb 2 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.