Executive Summary
In early 2026, the OpenClaw AI assistant ecosystem faced a significant supply chain attack known as 'ClawHavoc.' Threat actors uploaded over 1,100 malicious 'skills' to ClawHub, OpenClaw's official marketplace, disguising them as legitimate productivity tools. These malicious skills, once installed, deployed various malware, including the Atomic macOS Stealer (AMOS), compromising user credentials, cryptocurrency wallets, and sensitive documents. The attack exploited the trust users placed in ClawHub's skill repository, leading to widespread data breaches and system compromises.
This incident underscores the evolving threat landscape targeting AI agent ecosystems. The ease of creating and distributing malicious skills highlights the urgent need for robust security measures, including stringent code audits, supply chain verification practices, and user education on the risks associated with third-party extensions.
Why This Matters Now
The ClawHavoc attack exemplifies the growing trend of supply chain attacks targeting AI agent platforms. As these platforms become integral to business operations, ensuring the security of their ecosystems is paramount to prevent data breaches and maintain user trust.
Attack Path Analysis
Attackers uploaded malicious skills to ClawHub, leading to the compromise of OpenClaw agents. These agents, once compromised, escalated privileges to access sensitive data and moved laterally within networks. They established command and control channels to exfiltrate data, resulting in significant impact on affected organizations.
Kill Chain Progression
Initial Compromise
Description
Attackers uploaded malicious skills to ClawHub, which users downloaded and executed, leading to the compromise of OpenClaw agents.
Related CVEs
CVE-2026-25253
CVSS 8.8An authentication token leakage vulnerability in OpenClaw allows attackers to gain full administrative control over the gateway by tricking users into visiting a malicious site or clicking a malicious link.
Affected Products:
OpenClaw OpenClaw – < 2026.1.29
Exploit Status:
exploited in the wildCVE-2026-24763
CVSS 8.8A command injection vulnerability in OpenClaw allows attackers to execute arbitrary commands on the host system by exploiting insufficient input validation.
Affected Products:
OpenClaw OpenClaw – < 2026.1.29
Exploit Status:
exploited in the wildCVE-2026-25157
CVSS 7.5A command injection vulnerability in OpenClaw allows attackers to execute arbitrary commands on the host system by exploiting insufficient input validation.
Affected Products:
OpenClaw OpenClaw – < 2026.1.29
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Compromise Software Supply Chain
Compromise Software Dependencies and Development Tools
System Binary Proxy Execution
Obtain Capabilities: Malware
Obtain Capabilities: Tool
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Application Security
Control ID: 500.08
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Data Security
Control ID: Pillar 3: Data
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
OpenClaw supply chain attacks threaten financial institutions through malicious AI agent skills, potentially compromising encrypted traffic and enabling data exfiltration from trading systems.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations as OpenClaw vulnerabilities enable lateral movement through patient data systems and unauthorized access to medical records.
Information Technology/IT
IT sector experiences direct impact from 530 OpenClaw vulnerabilities enabling privilege escalation and command injection across multi-cloud environments and Kubernetes deployments.
Computer Software/Engineering
Software engineering firms vulnerable to malicious skills targeting development pipelines, with automated agents potentially compromising source code repositories and deployment infrastructure.
Sources
- OpenClaw: risks for the users and how to mitigate themhttps://securelist.com/openclaw-security/120484/Verified
- Key OpenClaw risks, Clawdbot, Moltbot | Kaspersky official bloghttps://www.kaspersky.com/blog/moltbot-enterprise-risk-management/55317/Verified
- Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Usershttps://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.htmlVerified
- OpenClaw Security Fallout: 341 Malicious Skills and Enabling One-Click Remote Code Executionhttps://winbuzzer.com/2026/02/03/openclaw-security-crisis-rce-malicious-skills-api-costs-xcxwbn/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to escalate privileges, move laterally, and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely limit the reach of compromised agents by enforcing strict workload isolation, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely constrain the compromised agents' ability to escalate privileges by enforcing strict identity-based access controls.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely restrict lateral movement by monitoring and controlling internal traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely detect and limit unauthorized outbound communications to external servers.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely restrict unauthorized data exfiltration by controlling outbound traffic.
While the initial compromise occurred, the implementation of Aviatrix Zero Trust CNSF would likely have limited the overall impact by containing the attacker's activities and preventing widespread data exfiltration.
Impact at a Glance
Affected Business Functions
- Automated Task Management
- System Administration
- Data Processing
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive business data, including credentials and proprietary information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement strict validation and code review processes for all third-party skills before deployment.
- • Enforce zero trust segmentation to limit the access and capabilities of OpenClaw agents within the network.
- • Utilize egress security and policy enforcement to monitor and control outbound traffic from OpenClaw agents.
- • Deploy threat detection and anomaly response systems to identify and respond to unusual agent behaviors.
- • Regularly update and patch OpenClaw agents and associated components to mitigate known vulnerabilities.



