The content on this page was provided by an independent third party and syndicated by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Tabuga Think Tank presents its first report Perspectives on digitalization of the Dominican Republic

Tabuga Think Tank presents its first report Perspectives on digitalization of the Dominican Republic

The report was developed from interviews with leaders of the national technology ecosystem. SANTO DOMINGO, DN,

March 17, 2026

Students Turn Raw News Data Into Visual Stories at 2026 Newsmatics Hackathon in Brno

Students Turn Raw News Data Into Visual Stories at 2026 Newsmatics Hackathon in Brno

High school, undergraduate and graduate students competed over 24 hours to analyze news trends, forecast future cycles,

March 17, 2026

Your Doctors Online Reports Serving More Than 1 Million Patients Through Its Virtual Healthcare Platform

Your Doctors Online Reports Serving More Than 1 Million Patients Through Its Virtual Healthcare Platform

Your Doctors Online says its telehealth platform has now served more than one million patients, reflecting growing

March 17, 2026

Author Michaele Aldophe Announces New Romantic Novel ‘Still, I Remember You’

Author Michaele Aldophe Announces New Romantic Novel ‘Still, I Remember You’

A heartfelt story of love, distance, and destiny set between the romantic streets of Paris and the breathtaking shores

March 17, 2026

Why Patients Are Traveling to Playa del Carmen for Veneers and Cosmetic Dentistry in Mexico

Why Patients Are Traveling to Playa del Carmen for Veneers and Cosmetic Dentistry in Mexico

A1 Smile Design explains the types of dental veneers available in Mexico, their benefits, and why Playa del Carmen is a

March 17, 2026

Marcus Jordan Announced as 2026 Recording Artist of the Year Award

Marcus Jordan Announced as 2026 Recording Artist of the Year Award

The Gospel Artist Celebrates Award Win With New Music Announcement LOS ANGELES, CA, UNITED STATES, March 17, 2026

March 17, 2026

InSkin Laser Aesthetics Introduces the Matrix® Skin Renewal Platform: A Revolutionary Approach to Skin Health

InSkin Laser Aesthetics Introduces the Matrix® Skin Renewal Platform: A Revolutionary Approach to Skin Health

At InSkin Laser Aesthetics, our goal has always been to provide treatments that deliver real, visible results while

March 17, 2026

AUVSI CEO Testifies on Risks of Chinese Robotics and AI

AUVSI CEO Testifies on Risks of Chinese Robotics and AI

Securing America’s leadership in robotics will require both carrots and sticks.”— AUVSI President & CEO Michael

March 17, 2026

The Mahdavi Law Firm Launches Personal Injury Claims Quiz for Texans

The Mahdavi Law Firm Launches Personal Injury Claims Quiz for Texans

The Mahdavi Law Firm PLLC Announces the Launch of Its Personal Injury Claims Quiz, Giving Texans a New Way To Evaluate

March 17, 2026

SYDNEY BASED BLOG CHICKS LIFESTYLE MAGAZINE COMMENCE FEATURES ON AN ARRAY OF MOBILE PHONE RELATED MATTERS

SYDNEY BASED BLOG CHICKS LIFESTYLE MAGAZINE COMMENCE FEATURES ON AN ARRAY OF MOBILE PHONE RELATED MATTERS

Management of Blog Chicks confirmed to Metro Cities Media they will commence monthly feature posts in March ranging

March 17, 2026

Muse Treatment Alcohol & Drug Rehab Los Angeles Publishes Critical New Resource on Website Examining Withdrawal Treatment for Xylazine-Linked “Zombie Drug” Exposure

Muse Treatment Alcohol & Drug Rehab Los Angeles Publishes Critical New Resource on Website Examining Withdrawal Treatment for Xylazine-Linked “Zombie Drug” Exposure

LOS ANGELES, CA – March 17, 2026 – PRESSADVANTAGE – Muse Treatment Alcohol & Drug Rehab Los Angeles has released a comprehensive new educational resource…

March 17, 2026

Kilgore, Texas Series Debuts on ‘Gone to Texas’ Business Podcast Highlighting East Texas Manufacturing

Kilgore, Texas Series Debuts on ‘Gone to Texas’ Business Podcast Highlighting East Texas Manufacturing

Company leaders share stories of workforce strength, industrial readiness, and business growth in East Texas. Kilgore’s

March 17, 2026

EPC Group Launches AI Decision Intelligence Framework for Microsoft Power BI

EPC Group Launches AI Decision Intelligence Framework for Microsoft Power BI

New framework combines Copilot, Claude, ChatGPT, Gemini, Perplexity, and multi-model LLMs to transform Power BI and

March 17, 2026

MRC Rocket Inc Launches Full-Service Digital Marketing Agency for E-Commerce and Small Businesses

MRC Rocket Inc Launches Full-Service Digital Marketing Agency for E-Commerce and Small Businesses

MRC Rocket Inc launches digital marketing services including SEO, PPC, social media, and content strategy for

March 17, 2026

6 Reasons Why Today’s Construction Labor Environment Will Likely Increase Disputes & Litigation In 2026

6 Reasons Why Today’s Construction Labor Environment Will Likely Increase Disputes & Litigation In 2026

Fundamental changes in the U.S. construction labor market have occurred affecting costs, availability, capabilities and

March 17, 2026

Dr. Renee Thompson Announced as a Pre-Conference Speaker at the 2026 AONL Annual Conference in Chicago

Dr. Renee Thompson Announced as a Pre-Conference Speaker at the 2026 AONL Annual Conference in Chicago

Creating a healthy work culture doesn’t happen by chance, It happens when leaders are equipped to address behavior, set

March 17, 2026

LET’S TALK WOMXN CHICAGO PRESENTS THEIR SIXTH ANNUAL WOMEN’S HISTORY MONTH CELEBRATION ‘RETRO REVOLUTION DANCE PARTY’

LET’S TALK WOMXN CHICAGO PRESENTS THEIR SIXTH ANNUAL WOMEN’S HISTORY MONTH CELEBRATION ‘RETRO REVOLUTION DANCE PARTY’

Spend the evening in an unabashed celebration of women empowering women; this celebration is for all of Chicago

March 17, 2026

The Book of Revelation: Revealing the Salvation of God by Hegumen Abraam Sleman Now Available

The Book of Revelation: Revealing the Salvation of God by Hegumen Abraam Sleman Now Available

A Gospel-centered interpretation of Revelation revealing God’s salvation, Christ’s victory, and hope The Book of

March 17, 2026

Palm Beach Tan Tyler Expands Into Wellness With Red Light Therapy and Infrared Sauna Services

Palm Beach Tan Tyler Expands Into Wellness With Red Light Therapy and Infrared Sauna Services

Tyler location adds Red Light Therapy and Infrared Sauna to complement its premier tanning services TYLER, TX, UNITED

March 17, 2026

Injury Care Solutions Group: A Well-Known Wide Receiver and the Lisfranc Injury Explained

Injury Care Solutions Group: A Well-Known Wide Receiver and the Lisfranc Injury Explained

Dr. Greg Vigna highlights wide receiver's resilience after injury and underscores the value of evidence-based expert

March 17, 2026

Turf Distributors Expands Fulfillment with Strategic Transition of Cut & Deliver Operations to Ewing Outdoor Supply

Turf Distributors Expands Fulfillment with Strategic Transition of Cut & Deliver Operations to Ewing Outdoor Supply

Partnership Strengthens Nationwide Distribution, Enhances Contractor Access to Premium Turf Products Transitioning our

March 17, 2026

Mindmachines.com Introduces Enhanced RoshiWave Mind Machine with Advanced Brainwave Disentrainment Technology

Mindmachines.com Introduces Enhanced RoshiWave Mind Machine with Advanced Brainwave Disentrainment Technology

Dallas, Texas – March 17, 2026 – PRESSADVANTAGE – Mindmachines.com has announced significant enhancements to its

March 17, 2026

Rigert Treppenlifte AG Expands Home Elevators Installation Services for Two Story Homes Across Switzerland

Rigert Treppenlifte AG Expands Home Elevators Installation Services for Two Story Homes Across Switzerland

Küssnacht am Rigi, SZ – March 17, 2026 – PRESSADVANTAGE – Rigert Treppenlifte AG, a leading Swiss mobility solutions

March 17, 2026

Kick It 3v3 Soccer Announces 2026 World Tour with Events in Cities Hosting World Cup Matches

Kick It 3v3 Soccer Announces 2026 World Tour with Events in Cities Hosting World Cup Matches

Denver, Colorado – March 17, 2026 – PRESSADVANTAGE – Kick It 3v3 Soccer, a 3v3 soccer tournament series in the United

March 17, 2026

STT Security Services Reveals Importance of Emergency Response Coordination in Security Services

STT Security Services Reveals Importance of Emergency Response Coordination in Security Services

MT. PLEASANT, MI – March 17, 2026 – PRESSADVANTAGE – STT Security Services has revealed the importance of emergency

March 17, 2026

East Dulwich Invisible Braces Teeth Straightening Dentist Dr Mori Shahid Recommends Invisalign Consultations at The Gardens Dental Centre (Smile 4 U)

East Dulwich Invisible Braces Teeth Straightening Dentist Dr Mori Shahid Recommends Invisalign Consultations at The Gardens Dental Centre (Smile 4 U)

London, England – March 17, 2026 – PRESSADVANTAGE – The Gardens Dental Centre (Smile 4 U) in East Dulwich has announced

March 17, 2026

First Black Person Expands to 37 Profiles Across 250 Years of History

First Black Person Expands to 37 Profiles Across 250 Years of History

March 17, 2026 – PRESSADVANTAGE – First Black Person, an educational reference documenting historic achievements by

March 17, 2026

Big Easy Paintings Expands Service Offerings With Professional Paint Color Selection for Homeowners

Big Easy Paintings Expands Service Offerings With Professional Paint Color Selection for Homeowners

NEW ORLEANS, LA – March 17, 2026 – PRESSADVANTAGE – Big Easy Paintings has formalized its Paint Color Selection service

March 17, 2026

Dietz Electric Expands Custom Motor Modification Capabilities

Dietz Electric Expands Custom Motor Modification Capabilities

MILWAUKEE, WI – March 17, 2026 – PRESSADVANTAGE – Dietz Electric has announced the expansion of its custom motor

March 17, 2026

Time Off Editing Announces Expanded Real Estate Photo Editing Services to Support Property Marketing and Visual Presentation

Time Off Editing Announces Expanded Real Estate Photo Editing Services to Support Property Marketing and Visual Presentation

Los Angeles, California – March 17, 2026 – PRESSADVANTAGE – Time Off Editing has announced the continued development of

March 17, 2026

Amana Care Clinic Announces Enhanced Walk-In Medical Services Across Quad Cities Region

Amana Care Clinic Announces Enhanced Walk-In Medical Services Across Quad Cities Region

DAVENPORT, Iowa – March 17, 2026 – PRESSADVANTAGE – Amana Care Clinic has announced enhanced walk-in medical services

March 17, 2026

Now Available: New Leadership Book No Shortcuts: What It Really Takes Confronts the Problem of Leadership Drift

Now Available: New Leadership Book No Shortcuts: What It Really Takes Confronts the Problem of Leadership Drift

Released during National Ethics Month, the book is already drawing attention from business leaders across industries.

March 17, 2026

McCarthy & Akers, PLC Sharpens Its Sole Focus on Estate Planning

McCarthy & Akers, PLC Sharpens Its Sole Focus on Estate Planning

McCarthy & Akers Announces Its Exclusive Focus on Estate Planning, Dedicating Full Attention to Holistic,

March 17, 2026

SPARK ’26 Brings Together Tamil Tech Entrepreneurs, Investors, Industry Leaders for a National Innovation Summit in NJ

SPARK ’26 Brings Together Tamil Tech Entrepreneurs, Investors, Industry Leaders for a National Innovation Summit in NJ

SPARK represents the energy and momentum of Tamil entrepreneurs in the technology sector,”— representatives from the

March 17, 2026

SAF Win: Post Office Carry Ban Injunction Covers Current and Future Members

SAF Win: Post Office Carry Ban Injunction Covers Current and Future Members

SAF Win: Post Office Carry Ban Injunction Covers Current and Future Members This is a huge win for current and future

March 17, 2026

Broadway Welcomes a New Wave of Shows as the World Cup Draws Worldwide Visitors

Broadway Welcomes a New Wave of Shows as the World Cup Draws Worldwide Visitors

NEW YORK, NY, UNITED STATES, March 17, 2026 /EINPresswire.com/ — As the NYC area prepares to host soccer fans during

March 17, 2026

AGPROfessionals Founder Tom Haren Named a 2026 ‘Leader in Agriculture’ by Denver Business Journal

AGPROfessionals Founder Tom Haren Named a 2026 ‘Leader in Agriculture’ by Denver Business Journal

GREELEY, CO, UNITED STATES, March 17, 2026 /EINPresswire.com/ — AGPROfessionals proudly announces that Founder and CEO

March 17, 2026

BaRupOn Healthcare Strengthens U.S. Medical Infrastructure

BaRupOn Healthcare Strengthens U.S. Medical Infrastructure

BaRupOn Healthcare integrates pharmacy, distribution, and biomedical innovation to strengthen U.S. healthcare supply

March 17, 2026

Aesthetic Expert Linda Rank Featured at VIP Oscars Gifting Lounge in Beverly Hills

Aesthetic Expert Linda Rank Featured at VIP Oscars Gifting Lounge in Beverly Hills

VIP Beverly Hills gifting lounge featured national trainer Linda Rank of Orange County, known for natural results and

March 17, 2026

Network Strategics Launches New AI Chat Agent Integration Service

Network Strategics Launches New AI Chat Agent Integration Service

New AI agent helps enhance lead qualification, supports instant responses, and integrates seamlessly at competitive

March 17, 2026