The content on this page was provided by an independent third party and syndicated by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

NextDAY Cabinets Beltsville Showroom Expands Kitchen Cabinets Selection with Enhanced Design Services for Maryland Contractors

NextDAY Cabinets Beltsville Showroom Expands Kitchen Cabinets Selection with Enhanced Design Services for Maryland Contractors

BELTSVILLE, MD – March 18, 2026 – PRESSADVANTAGE – NextDAY Cabinets Beltsville Showroom has expanded its wholesale

March 18, 2026

The Club at Mediterra Maintains Elite Status, Announces New Sports & Lifestyle Center

The Club at Mediterra Maintains Elite Status, Announces New Sports & Lifestyle Center

Elite recognition and strategic investment reinforce Mediterra’s position among the nation’s top private clubs. Our

March 18, 2026

Public Health Action Network Is Accepting Proposals for Projects That Reduce Transmission of Airborne Pathogens

Public Health Action Network Is Accepting Proposals for Projects That Reduce Transmission of Airborne Pathogens

PHAN welcomes proposals from individuals, researchers, engineers, public health practitioners, and innovators committed

March 18, 2026

Voggia Introduces a New Editorial Standard for Gastronomy, Style, and the Modern Good Life

Voggia Introduces a New Editorial Standard for Gastronomy, Style, and the Modern Good Life

Istanbul-based Voggia publishes in English and Turkish, offering a research-driven perspective on fine dining, cocktail

March 18, 2026

Taylor Voiselle Featured on Next Level CEO

Taylor Voiselle Featured on Next Level CEO

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Taylor Voiselle, founder of PRIMARIX Inc., is set to appear on

March 18, 2026

ALM Automotive Expands Middle Georgia Presence With Acquisition of 5 Major Dealerships

ALM Automotive Expands Middle Georgia Presence With Acquisition of 5 Major Dealerships

ATLANTA, GA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — ALM Automotive, one of the Southeast’s fastest‑growing

March 18, 2026

Qalitex Laboratories Expands Mycotoxin Testing Capabilities

Qalitex Laboratories Expands Mycotoxin Testing Capabilities

ISO 17025 lab outlines aflatoxin, ochratoxin, and fumonisin testing for supplement brands against FDA, USP

March 18, 2026

Jarryd Loyd Featured on Next Level CEO

Jarryd Loyd Featured on Next Level CEO

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Jarryd Loyd, a leader in finance and private equity, is set to

March 18, 2026

Dr. Natasha Williams Delivers Transformative Black History Month Address at Vermont State University

Dr. Natasha Williams Delivers Transformative Black History Month Address at Vermont State University

International psychologist Dr. Natasha Williams shares insights on self-care, leadership, and sustainable success

March 18, 2026

Liv Hospital Launches Comprehensive Guide to Recognize Early Cancer Symptoms and Improve Early Detection

Liv Hospital Launches Comprehensive Guide to Recognize Early Cancer Symptoms and Improve Early Detection

NEW YORK, NY, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Liv Hospital today launched an informative guide to

March 18, 2026

Alex Baldwin Joins Operation CEO

Alex Baldwin Joins Operation CEO

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Alex Baldwin, founder of Minnesota Structures, is set to appear

March 18, 2026

Introducing the Agent Skills Security Index

Introducing the Agent Skills Security Index

The Agent Skills Security Index community powered by Tego is a public database that analyzes and maps security risks

March 18, 2026

Sage Bionetworks Partners with NYU Langone Health to Build Data Infrastructure for NIH’s Complement-ARIE Program

Sage Bionetworks Partners with NYU Langone Health to Build Data Infrastructure for NIH’s Complement-ARIE Program

New data hub will accelerate development and adoption of human-based New Approach Methodologies The NYU Langone-Sage

March 18, 2026

Rip Tie Hair Lands $250K Shark Tank Deal with Lori Greiner and Poppi Founder Allison Ellsworth

Rip Tie Hair Lands $250K Shark Tank Deal with Lori Greiner and Poppi Founder Allison Ellsworth

What started as a bad hair day after a scuba dive in Guam turned into a company that has sold more than 500,000 units —

March 18, 2026

Stanton University MBA Capstone Showcases Real-World Business Solutions and Future-Ready Leaders

Stanton University MBA Capstone Showcases Real-World Business Solutions and Future-Ready Leaders

ANAHEIM, CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Graduate students at Stanton University reached a

March 18, 2026

Dr. Grant Elliott Featured on Next Level CEO

Dr. Grant Elliott Featured on Next Level CEO

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Dr. Grant Elliott, founder of RehabFix, is set to appear on

March 18, 2026

Metrovolo Launches Private AI Platform for Professional Services Firms

Metrovolo Launches Private AI Platform for Professional Services Firms

New managed service deploys AI on firm-controlled infrastructure, keeping sensitive client data away from outside AI

March 18, 2026

CHANTAL MCNEILY SELECTED AS TOP GLOBAL FINANCIAL EMPOWERMENT LEADER OF THE YEAR BY IAOTP

CHANTAL MCNEILY SELECTED AS TOP GLOBAL FINANCIAL EMPOWERMENT LEADER OF THE YEAR BY IAOTP

The International Association of Top Professionals (IAOTP) will honor Chantl McNeily at their annual awards gala in NYC

March 18, 2026

FAA’s Streamlined Part 91 Letters of Authorization Process Made Easier with Nimbl Guide

FAA’s Streamlined Part 91 Letters of Authorization Process Made Easier with Nimbl Guide

Guide Explains Benefits, Who Qualifies, and How to Submit Multiple Applications to Reduce Approval Timelines ROCKVILLE,

March 18, 2026

Eric Doctorow’s Imaginative PORTRAITS Book Now Available

Eric Doctorow’s Imaginative PORTRAITS Book Now Available

Book Imagines a Single Face Painted By History’s Greatest Painters Across Time and Imagined eras—from Pompeii to the

March 18, 2026

Haven Treatment Center Announces Milestone After Passing State Fire Inspection, Expanding Foster Care Bed Availability

Haven Treatment Center Announces Milestone After Passing State Fire Inspection, Expanding Foster Care Bed Availability

Haven Treatment Center Clears Key Safety Hurdle, Paving the Way for Expanded Foster Care Capacity VANCOUVER, WA, UNITED

March 18, 2026

MountainWest Capital Network Names Mary Crafts 2026 Entrepreneur of the Year

MountainWest Capital Network Names Mary Crafts 2026 Entrepreneur of the Year

MountainWest Capital Network (MWCN) proudly honored entrepreneur, author, and speaker Mary Crafts as the 2026

March 18, 2026

Wilder Ranch Community Underway in Teton Valley

Wilder Ranch Community Underway in Teton Valley

3,250-Acre Ranch Community on the Quiet Side of the Tetons I grew up coming to the Teton Valley with my family for pack

March 18, 2026

Sifter Solutions, Inc. Partners with Brookshire Brothers, Inc. to Support SNAP Waiver Compliance & Health-Focused Retail

Sifter Solutions, Inc. Partners with Brookshire Brothers, Inc. to Support SNAP Waiver Compliance & Health-Focused Retail

FOR IMMEDIATE RELEASE Ensuring our stores remain prepared for evolving SNAP waiver requirements while continuing to

March 18, 2026

Elvictor Group Announces Approval of Reverse Stock Split

Elvictor Group Announces Approval of Reverse Stock Split

ATTIKI, GREECE / ACCESS Newswire / March 18, 2026 / Elvictor Group Inc. (OTCID:ELVG) ("Elvictor" or the "Company"), a

March 18, 2026

Babytree Surrogacy Outlines the Complete Babytree Surrogacy Process for Intended Parents in California

Babytree Surrogacy Outlines the Complete Babytree Surrogacy Process for Intended Parents in California

March 18, 2026 – PRESSADVANTAGE – Babytree Surrogacy, a leading surrogacy agency in California, has published a

March 18, 2026

Precision Reloading Expands BoreTech Cleaning Products Selection for Firearm Maintenance

Precision Reloading Expands BoreTech Cleaning Products Selection for Firearm Maintenance

MITCHELL, SD – March 18, 2026 – PRESSADVANTAGE – Precision Reloading has expanded its inventory of professional-grade

March 18, 2026

IntroDrink Releases Comprehensive Guide on Natural Magnesium Supplementation for Swiss Health Consumers

IntroDrink Releases Comprehensive Guide on Natural Magnesium Supplementation for Swiss Health Consumers

Zurich, Zurich – March 18, 2026 – PRESSADVANTAGE – IntroDrink, a leading Swiss online retailer of premium natural

March 18, 2026

Amana Care Clinic Emphasizes Walk-In Medical Services for Muscatine Area Residents

Amana Care Clinic Emphasizes Walk-In Medical Services for Muscatine Area Residents

MUSCATINE, Iowa – March 18, 2026 – PRESSADVANTAGE – Amana Care Clinic – Muscatine continues to address the growing

March 18, 2026

Dr. Michael Alcée, Respected Psychologist and Author, Says Healing From OCD Begins With Understanding, Not Fear or Doubt

Dr. Michael Alcée, Respected Psychologist and Author, Says Healing From OCD Begins With Understanding, Not Fear or Doubt

The author of The Upside of OCD encourages people living with OCD to embrace who they are, rather than trying to erase

March 18, 2026

Sticky Brand Included in The Boston Globe’s list of New England’s Fastest Growing Companies 2026

Sticky Brand Included in The Boston Globe’s list of New England’s Fastest Growing Companies 2026

BURLINGTON, VT, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Sticky Brand is proud to announce its inclusion in

March 18, 2026

Straight-Leg Jeans Are Leading the New Era of Denim in 2026

Straight-Leg Jeans Are Leading the New Era of Denim in 2026

MIAMI, FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Denim is once again at the forefront of global fashion

March 18, 2026

Gillie and Marc Team Up with Sesame Street To Unveil New Public Art Collaboration at RXR’s 590 Madison Avenue on 3/20

Gillie and Marc Team Up with Sesame Street To Unveil New Public Art Collaboration at RXR’s 590 Madison Avenue on 3/20

The Nostalgic Official Unveiling Will Take Place at 590 Madison Avenue, In Midtown, On Friday, March 20, from 10 AM to

March 18, 2026

AMD Direct Highlights Outdoor Living Solutions at HPBExpo26 in New Orleans

AMD Direct Highlights Outdoor Living Solutions at HPBExpo26 in New Orleans

Summerset and TrueFlame products on display with live educational sessions and cooking tips HPBExpo gives us a focused

March 18, 2026

Heritage Signs & Displays Opens New Charlotte Headquarters

Heritage Signs & Displays Opens New Charlotte Headquarters

The 4-Acre Charlotte Campus Will Serve as HQ and Regional Production Facility for the Veteran-Led, Family-Owned Company

March 18, 2026

Sweet Briar Honored by Virginia General Assembly for 125 Years of Women’s Leadership

Sweet Briar Honored by Virginia General Assembly for 125 Years of Women’s Leadership

Virginia General Assembly honors Sweet Briar College on Women’s Colleges Day, celebrating 125 years of leadership and

March 18, 2026

A.I. Competitors Locking Down Infrastructure Deals, Mogin Law Analysis Shows

A.I. Competitors Locking Down Infrastructure Deals, Mogin Law Analysis Shows

Review of the Mogin Law A.I. Deal Table shows growing use of power generation, compute power and datacenter commitments

March 18, 2026

Climate Scientist Jonathan Foley Honored by American Association of Geographers

Climate Scientist Jonathan Foley Honored by American Association of Geographers

The AAG Confers its Top Honor, the Atlas Award, on Environmental Scientist Jonathan Foley, in San Francisco March 19 I

March 18, 2026

Techbridge Girls and Cloud Girls Launch Joint Fundraising Campaign to Expand Pathways for Girls in STEM

Techbridge Girls and Cloud Girls Launch Joint Fundraising Campaign to Expand Pathways for Girls in STEM

Techbridge Girls and Cloud Girls launch a joint fundraising campaign to support TBG’s work to reengineer STEM education

March 18, 2026

#1 B2B Podcast, The Travel Trends Podcast, Launches Season 7

#1 B2B Podcast, The Travel Trends Podcast, Launches Season 7

With Video and Celebrity Mentalist David Stryker This season is about understanding how the biggest decisions in travel

March 18, 2026