Tricky Profit
  • Stock
  • Economy
  • Politics
  • Editor’s Pick
Editor's Pick

Researchers warn OpenClaw users after malicious plugins surface on ClawHub

by February 9, 2026
by February 9, 2026 0 comment

OpenClaw’s plugin marketplace, ClawHub, has come under security scrutiny after researchers uncovered a large number of malicious plugins embedded within the platform.

Blockchain security firm SlowMist says gaps in the review process allowed harmful code to spread through plugins that appeared legitimate.

The findings highlight growing supply chain risks across fast-scaling AI ecosystems, where official plugin hubs are often trusted by developers.

As ClawHub gained traction among AI agent builders, its moderation systems failed to keep pace with growth, creating an opening for attackers to distribute unsafe code through everyday development tools.

Weak checks draw attention

SlowMist says ClawHub’s screening controls were not strict enough to detect hidden threats before publication.

Attackers allegedly submitted skills that looked useful on the surface but contained concealed commands capable of triggering harmful actions once installed.

Because plugins are hosted on an official OpenClaw platform, developers were more likely to follow installation instructions without deep inspection.

Researchers warn that this implicit trust increases exposure, allowing malicious code to propagate quietly across projects that reuse popular skills.

SlowMist

@SlowMist_Team

·Follow

🚨 Threat Intelligence | Analysis of ClawHub Malicious Skills Poisoning

As the #OpenClaw AI agent ecosystem rapidly grows, SlowMist has observed ClawHub becoming a new target for large-scale supply chain attacks. Due to insufficient review mechanisms, hundreds of malicious

8:35 AM · Feb 9, 2026

18

Reply

Read 3 replies

Scale of exposure emerges

Independent analysis suggests the issue is not limited to a handful of plugins. A separate scan by Koi Security reviewed 2,857 skills on ClawHub and flagged 341 as malicious.

SlowMist carried out its own investigation, tracking more than 400 threat indicators across the ecosystem.

That deeper review identified repeated technical patterns linking many of the unsafe skills.

According to researchers, the overlap points to an organised effort rather than isolated uploads.

Multiple plugins appeared to rely on similar infrastructure, indicating sustained activity rather than one-off abuse.

Installation process exploited

Researchers say the attacks hinge on how OpenClaw skills are structured. Many rely on instruction files that users execute directly during setup.

Attackers took advantage of this design by embedding hidden download-and-run commands within those instructions.

In several cases, the initial commands were obfuscated using encoded text to disguise their true function.

Once decoded and executed, the code quietly retrieved a secondary program from an external server.

That second-stage payload then performed the malicious activity.

This layered method makes detection more difficult and allows attackers to update the harmful component without changing the visible plugin listing, extending the lifespan of the threat.

Shared infrastructure raises red flags

SlowMist says its analysis linked many of the malicious skills to a small group of domains and server addresses, including 91.92.242.30.

The repeated use of the same infrastructure across different plugins suggests coordination and planning.

Security teams are now urging OpenClaw users to scrutinise installation steps carefully and avoid running unfamiliar commands.

Until stronger review and monitoring controls are implemented, researchers warn that ClawHub could remain an attractive target for supply chain-style attacks targeting AI developers.

The post Researchers warn OpenClaw users after malicious plugins surface on ClawHub appeared first on Invezz

0 comment
0
FacebookTwitterPinterestEmail

previous post
Native staking that finally makes sense: Ilya Tarutov on Tramplin.io Premium Staking
next post
Why address poisoning is becoming one of crypto’s costliest scams

You may also like

South Korea FSS to deploy AI crypto surveillance...

February 9, 2026

CoinShares says quantum computing threat to Bitcoin remains...

February 9, 2026

Why address poisoning is becoming one of crypto’s...

February 9, 2026

Native staking that finally makes sense: Ilya Tarutov...

February 9, 2026

HYPE gains 47%, outperforming BTC and ETH: Here’s...

February 9, 2026

Axie Infinity token price soars over 20% within...

February 9, 2026

Bitcoin outlook at risk as Bessent urges Senate...

February 9, 2026

XRP at a critical region after recent rebound:...

February 9, 2026

LATAM crypto: Argentina’s Bitcoin treasury, Brazil’s tokenization milestone

February 8, 2026

Bitget Fan Club sets a new standard for...

February 7, 2026

    Join our mailing list to get access to special deals, promotions, and insider information. Your exclusive benefits await! Enjoy personalized recommendations, first dibs on sales, and members-only content that makes you feel like a true VIP. Sign up now and start saving!


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Recent Posts

    • Gold reclaims $5,000, silver surges 6% as experts say bullish momentum intact

      February 9, 2026
    • Morning brief: Takaichi wins Japan election, Starmer’s chief of staff quits

      February 9, 2026
    • China is “selling” America, but the rest of the world is still buying

      February 9, 2026
    • Bitcoin outlook at risk as Bessent urges Senate to advance Warsh nomination

      February 9, 2026
    • Indian refiners buy 2M barrels of Venezuelan Merey crude: report

      February 9, 2026

    Disclaimer: TrickyProfit.com, its managers, its employees, and assigns (collectively "The Company") do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice.
    The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

    • About us
    • Contacts
    • Privacy Policy
    • Terms and Conditions
    • Email Whitelisting

    Copyright © 2025 TrickyProfit.com All Rights Reserved.

    Tricky Profit
    • Stock
    • Economy
    • Politics
    • Editor’s Pick