Malicious plugins discovered in OpenClaw’s ClawHub attack

OpenClaw's ClawHub marketplace faced a supply chain attack, with hundreds of malicious plugins spreading malware and stealing data. Experts urge stronger plugin review and user caution.

OpenClaw's ClawHub plugin marketplace recently suffered a major supply chain attack. Security researchers uncovered hundreds of malicious plugins embedded within the platform, exploiting weak review mechanisms. Attackers uploaded harmful skills disguised as legitimate tools, often targeting cryptocurrency, security, and automation sectors. These plugins used advanced evasion techniques, such as hiding malicious commands in SKILL.md files and employing Base64 encoding. Once installed, they could steal credentials, extract sensitive data, and deploy malware like keyloggers or the Atomic Stealer. Security firms SlowMist and KOI Security identified between 341 and 472 malicious plugins among thousands available. This incident highlights the risks of implicit trust in official repositories and the urgent need for stricter review processes. Users should scrutinize installation instructions, avoid unverified commands, and only download from trusted sources to stay secure.

Related News