{"id":370913,"date":"2026-06-25T06:32:00","date_gmt":"2026-06-25T13:32:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/en\/?p=370913"},"modified":"2026-06-25T06:32:47","modified_gmt":"2026-06-25T13:32:47","slug":"clawhub-caught-hosting-five-malicious-openclaw-skills-two-hit-macs","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/clawhub-caught-hosting-five-malicious-openclaw-skills-two-hit-macs\/","title":{"rendered":"ClawHub caught hosting five malicious OpenClaw skills: two hit Macs"},"content":{"rendered":"<p class=\"wp-block-paragraph\">In <strong>June 2026<\/strong>, Palo Alto Networks&#8217; Unit 42 reported that ClawHub, the official marketplace for <a href=\"https:\/\/openclaw.en.softonic.com\/\" rel=\"noopener\">OpenClaw<\/a>, had exposed developers and other power users to a supply chain attack. OpenClaw launched in November 2025 as an open-source agent that can browse the web, manage files, and take actions on a user&#8217;s system. Unit 42 said ClawHub distributed five malicious OpenClaw skills, including two that installed Atomic macOS Stealer on Macs.<\/p>\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Malwarebytes Anti-Malware\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/c4cf3a2e-99ea-11e6-8662-00163ec9f5fa\/94049179\/malwarebytes-anti-malware-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Malwarebytes Anti-Malware<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/malwarebytes-anti-malware.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/malwarebytes-anti-malware.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Unit 42 said two of those packages dropped Atomic macOS Stealer. One of them <strong>slipped past both<\/strong> <a href=\"https:\/\/virustotal-uploader.en.softonic.com\/\" rel=\"noopener\">VirusTotal<\/a> and ClawScan by padding its README beyond the scanners&#8217; size limits. The researchers also said two other packages were built for commission fraud.<\/p>\n\n<p class=\"wp-block-paragraph\">They also found <strong>persistence and evasion<\/strong> techniques, which points to a broader problem in how sensitive skills are reviewed.<\/p>\n\n<p class=\"wp-block-paragraph\">Bitdefender Labs had already sounded the alarm in February 2026, warning that about <strong>17%<\/strong> of the OpenClaw skills it analyzed showed malicious behavior. Bitdefender said many of those skills posed as utility tools, especially crypto-related ones, and used hidden commands to download malware or quietly tamper with transactions, affiliate links, and crypto activity.<\/p>\n\n<p class=\"wp-block-paragraph\">If you use OpenClaw regularly, take this seriously. The affected skills were published through ClawHub, OpenClaw&#8217;s official marketplace.<\/p>\n\n<p class=\"wp-block-paragraph\">According to Unit 42, OpenClaw has since <strong>removed the affected<\/strong> skills and banned the publishers. Security experts are still pushing for stricter publisher vetting, line-by-line audits for high-risk packages, and a formal review process so third-party skills don&#8217;t end up becoming shadow IT inside your company.<\/p>","protected":false},"excerpt":{"rendered":"<p>In June 2026, Palo Alto Networks&#8217; Unit 42 reported that ClawHub, the official marketplace for OpenClaw, had exposed developers and other power users to a supply chain attack. OpenClaw launched in November 2025 as an open-source agent that can browse the web, manage files, and take actions on a user&#8217;s system. Unit 42 said ClawHub &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/clawhub-caught-hosting-five-malicious-openclaw-skills-two-hit-macs\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;ClawHub caught hosting five malicious OpenClaw skills: two hit Macs&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9229,"featured_media":370912,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[6771],"class_list":["post-370913","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","content-category-ai"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9229"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=370913"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370913\/revisions"}],"predecessor-version":[{"id":370914,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370913\/revisions\/370914"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/370912"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=370913"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=370913"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=370913"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=370913"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=370913"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=370913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}