Researchers have identified malicious skills within OpenClaw's ClawHub marketplace that evade automated detection. These skills are designed to deploy information-stealing malware and conduct automated financial fraud.

OpenClaw, a platform for AI agents that execute third-party skills from its dedicated marketplace, ClawHub, has been targeted by persistent and evolving malicious campaigns. These attacks leverage the unique architecture of AI agent ecosystems, where skills, defined by markdown-driven packages, possess broad access to local systems, making ClawHub a critical vulnerability in the agentic software supply chain.
Early campaigns, reported in February 2026, saw a significant number of malicious skills on ClawHub. Bitdefender Labs found that approximately 17% of analyzed OpenClaw skills contained malicious payloads in the platform's initial weeks. Koi Security's "ClawHavoc" disclosure identified 341 malicious skills, and Trend Micro confirmed skills distributing Atomic macOS Stealer (AMOS) malware. These early attacks employed various techniques, including Base64-encoded `curl-pipe-bash` droppers, platform-specific delivery mechanisms, and persistence through auto-updaters that registered scheduled cron jobs. Some attackers also used alternative exfiltration channels, such as the Telegram Bot API, for cryptocurrency private keys. A notable tactic involved a single publisher injecting identical malicious payloads into most of their skill catalog to maximize installation surface.
These initial findings prompted ClawHub to implement proactive screening measures, integrating VirusTotal and its own ClawScan tool to analyze code and block malicious skills from download. However, analysis conducted between February and May 2026 revealed that malicious skills continued to evade these detection mechanisms. Five such unblocked skills were identified and subsequently reported to ClawHub, leading to the banning of associated accounts and the deletion of the skills.
These five skills fell into three distinct threat categories. Two were macOS infostealers, connecting to command-and-control (C2) infrastructure, indicating ongoing threat actor activity. One skill employed an evasion technique by inflating its file size to exceed scanner thresholds, thereby bypassing both ClawScan and VirusTotal. The remaining two skills represented novel agentic threats: runtime agentic affiliate injection and agentic front-running, both designed for financial gain.
The AMOS dropper infrastructure from the earlier campaigns remained active for over three months after its public disclosure, with the C2 server at 91.92.242[.]30 continuing to receive new skill deliveries. Additionally, new attacks emerged that adapted to and exploited skill marketplaces, leveraging the agentic execution model to implement financial schemes that evaded some forms of malware detection.
One specific instance involved two skills published on May 17, 2026, targeting TradingView users. These skills, posing as AI assistants for macOS traders, embedded a malicious prerequisite block. This block directed agents to a paste-site redirect lure at `hxxps[:]//rentry[.]co/openclaw-code`, which provided instructions for copying and pasting a Base64-encoded string into a terminal. Executing this command fetched a macOS infostealer named `cluw` (SHA256 hash: `818aea6143282b352fdfdc0f3ebf77a36e54eb3befb5cad1a355a99ab97c6aa7`) from `hxxp[:]//2.26.75[.]16/Xuvewuyur`. This delivery mechanism mirrored the "ClawHavoc" campaigns previously documented.
OpenClaw is now collaborating with NVIDIA to enhance skill screening. This partnership aims to provide detailed documentation of each skill's functionality and to run NVIDIA's analysis tools on all published skills. This initiative seeks to further strengthen the security posture of the ClawHub marketplace against the evolving landscape of AI supply chain threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed