• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - AI Trends and Related News - Be careful when downloading OpenClaw skills! International cybersecurity teams report that over 200 malicious skills have been found on ClawHub and GitHub.

Be careful when downloading OpenClaw skills! International cybersecurity teams report that over 200 malicious skills have been found on ClawHub and GitHub.

Rocky by Rocky
February 2, 2026 - Updated on August 4, 2026
in AI Trends and Related News

to use OpenClaw Generally, to achieve more automation or connect external services, installing Skills is required. However, you now need to be especially careful. According to the latest foreign security research team’s report, the well-known ClawHub and GitHub On the platform, more than 200 Skills containing malicious code have been discovered, disguised as cryptocurrency automated trading tools, but actually will macOS and Windows Malicious software that secretly steals information


Image source: OpenSourceMalware

OpenClaw Users, Don’t Install Carelessly! Malicious Code Found in Skills on Both ClawHub and GitHub

According to the OpenSourceMalware security research team, 28 malicious skills were initially uploaded to ClawHub and GitHub between January 27-29, 2026, followed by over 200 additional Skills on January 31 to February 1, bringing the total to over 230.


Image source: OpenSourceMalware

Interestingly, however, all the skills currently containing malicious code are related to cryptocurrency trading bots, making it clear that the intent is to steal users’ cryptocurrency.


Image source: OpenSourceMalware

According to sources, this technique involves packaging malicious processes as seemingly legitimate installation or setup tutorials, such as asking you to copy and paste what appears to be an “initialization” command when setting up an exchange, wallet, or automation workflow.

Because the instruction content is obfuscated, fragmented, and made less readable in various ways, experienced developers might notice it right away, but for regular users, they’ll just think “just follow the steps to complete setup.” In reality, this command is actually downloading and executing a remote script, allowing info-stealing malware to be placed in your environment.


Image source: OpenSourceMalware

Next, the infostealer will start searching for cryptocurrency-related API keys, wallet files, and browser extension wallets on your computer. It will even scan macOS Keychain, SSH keys, AWS/Gcloud credentials, Git credentials, or .env files.

These malicious Skills simultaneously target both Windows and macOS users, spreading through extensive social engineering tactics.

According to Tom’s Hardware, one of the Skills flagged as malicious once appeared on the ClawHub homepage, suggesting that quite a few people may have mistakenly installed it before it was removed.

To enable OpenClaw to automate the tools you want, you sometimes have to install Skills. However, always make sure to use trusted sources—don’t just try out something you see shared online unless you fully understand the commands and carefully review every installation step.


Image source: OpenSourceMalware

During OpenSourceMalware’s investigation of the AI Skills login platform, they discovered that ClawHub currently shows no evidence that Skills undergo any security scanning, so users should exercise extra caution.

As agentic AI tools gain more attention, incidents involving malicious code are expected to increase. For those without any technical background, it’s recommended to wait until the technology is more mature and secure before trying it.

Source: KOCPC Chinese

Tags: aiAI AGENTArtificial IntelligenceClawdbotOpenClaw

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology