The content on this page was provided by an independent third party and syndicated by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

R.M. Almonte Continues 50-State Book Tour with 49 States Completed and Wisconsin Remaining

R.M. Almonte Continues 50-State Book Tour with 49 States Completed and Wisconsin Remaining

R.M. Almonte Continues 50-State Book Tour with 49 States Completed and Wisconsin Remaining MILWAUKEE, WI, UNITED

March 18, 2026

San Diego BMW Motorcycles Invites All Riders to Scenic Sunrise Highway Group Ride on March 21

San Diego BMW Motorcycles Invites All Riders to Scenic Sunrise Highway Group Ride on March 21

Join riders of all brands for a stunning Sunrise Highway adventure: pine forests, desert views, Mount Laguna, and Lake

March 18, 2026

Lagos-Born Artist Chinedu Victor Opens Solo Exhibition ‘Memories of an Undocumented Past’ in New York

Lagos-Born Artist Chinedu Victor Opens Solo Exhibition ‘Memories of an Undocumented Past’ in New York

DFN Projects is pleased to present Memories of an Undocumented Past, the debut solo exhibition by Chinedu Victor,

March 18, 2026

Groundbreaking AI-Generated Documentary on Science and Faith Premieres April 8

Groundbreaking AI-Generated Documentary on Science and Faith Premieres April 8

In an era of high anxiety about artificial intelligence, one former Harvard physicist is using it to explore God.

March 18, 2026

Intelligent Diva Shatters Industry Norms with Human-AI Hybrid Single ‘Nobody Like You’ & Enterprise-Grade Tech Ecosystem

Intelligent Diva Shatters Industry Norms with Human-AI Hybrid Single ‘Nobody Like You’ & Enterprise-Grade Tech Ecosystem

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — High-tech visionary and recording artist Intelligent Diva

March 18, 2026

VegasAilure.com Launches ‘Agent Ailure’: The First Agentic AI Travel Architect for the Las Vegas Strip

VegasAilure.com Launches ‘Agent Ailure’: The First Agentic AI Travel Architect for the Las Vegas Strip

New custom GPT and workspace platform turn ChatGPT trip planning into system-verified Las Vegas itineraries and

March 18, 2026

Paramount Roofing Announces Plymouth, MI Expansion with Official Ribbon Cutting Ceremony

Paramount Roofing Announces Plymouth, MI Expansion with Official Ribbon Cutting Ceremony

New location at 963 W Ann Arbor Trail strengthens service across Metro Detroit with faster inspections, estimates, and

March 18, 2026

The Birth of a New Dark Hero! Ultra-Violent Action Saga ‘TANK CHAIR-戦車椅子-‘ Anime Series: Coming Fall 2026

The Birth of a New Dark Hero! Ultra-Violent Action Saga ‘TANK CHAIR-戦車椅子-‘ Anime Series: Coming Fall 2026

New “TANK CHAIR” teaser, trailer, and screenshots revealed! Staff comments are in, and the official Discord fan club is now OPEN! Join the global community…

March 18, 2026

Epic Authenticity, Permission Granted Speaking Tour from the Creator of Women for Women Today

Epic Authenticity, Permission Granted Speaking Tour from the Creator of Women for Women Today

WESTWOOD, NJ, UNITED STATES, March 18, 2026 /EINPresswire.com/ — T.H. Irwin, MBA, a veteran experiential creator and

March 18, 2026

ANNE SCHAEDDEL SELECTED FOR TOP 50 FEARLESS LEADERS BY IAOTP

ANNE SCHAEDDEL SELECTED FOR TOP 50 FEARLESS LEADERS BY IAOTP

The International Association of Top Professionals (IAOTP) will honor Anne Schaeddel at their annual awards gala in NYC

March 18, 2026

Currie Green Announces Expansion With New Building for Enhanced and Memory Care

Currie Green Announces Expansion With New Building for Enhanced and Memory Care

Currie Green expands its Calgary senior living campus with a new building for enhanced and memory care, supporting

March 18, 2026

Industry-Led Geofencing Project Kicks Off Support for Next Generation 6 GHz Unlicensed Devices

Industry-Led Geofencing Project Kicks Off Support for Next Generation 6 GHz Unlicensed Devices

WInnForum launches a new effort to define and test Geofenced Variable Power (GVP) device capabilities and incumbent

March 18, 2026

Halemont Capital Expands Strategic Capital Advisory Support for Founders Preparing for Meaningful Raises

Halemont Capital Expands Strategic Capital Advisory Support for Founders Preparing for Meaningful Raises

Halemont Capital helps founders strengthen investor positioning, capital structure, and negotiation readiness before

March 18, 2026

The Invisible Everywhere: Scientist Explains Why Modern Physics Points to God in New Documentary

The Invisible Everywhere: Scientist Explains Why Modern Physics Points to God in New Documentary

Dr. Michael Guillén says his deep understanding of science — including modern cosmology and human consciousness —

March 18, 2026

DreamCollege.ai Launches School Edition to Scale Personalized College Admissions Guidance

DreamCollege.ai Launches School Edition to Scale Personalized College Admissions Guidance

New Human + AI platform helps schools expand personalized college admissions guidance, increase counselor capacity, and

March 18, 2026

Michigan Entrepreneurs to Converge in Southfield for High-Stakes Pitch Competition and Business Expo

Michigan Entrepreneurs to Converge in Southfield for High-Stakes Pitch Competition and Business Expo

Pitch competitions are a powerful catalyst for innovation, giving entrepreneurs a platform to showcase their ideas and

March 18, 2026

Historic Petaluma Landmark ‘Hall of the Above’ Celebrates 100 Years with Centennial Party on April 25

Historic Petaluma Landmark ‘Hall of the Above’ Celebrates 100 Years with Centennial Party on April 25

Hall of the Above marks 100 years since the building first opened to the public with a special centennial celebration

March 18, 2026

Legendary Fire Instructors Converge in Colorado Springs Focused on Interior Attacks in High-Rise and Big-Box Fires

Legendary Fire Instructors Converge in Colorado Springs Focused on Interior Attacks in High-Rise and Big-Box Fires

Fire in the Sky 2026 Unites Veterans from FDNY, Chicago, Seattle, Denver and Beyond for Three Days of High-Rise and

March 18, 2026

Jason Ruedy Says Fort Collins Investors Are Turning to DSCR Loans for Rental Properties

Jason Ruedy Says Fort Collins Investors Are Turning to DSCR Loans for Rental Properties

Fort Collins Mortgage Expert Jason Ruedy “The Home Loan Arranger” Says DSCR Loans Are Helping Real Estate Investors

March 18, 2026

Cor Consulting Broadens Industry Reach Beyond Telecom With Automotive and AI-Focused Initiatives

Cor Consulting Broadens Industry Reach Beyond Telecom With Automotive and AI-Focused Initiatives

Cor Consulting expands beyond telecom, entering automotive services and exploring AI partnerships to better support

March 18, 2026

Arab America Foundation Announces 20 Under 20 Awardees-Class of 2026

Arab America Foundation Announces 20 Under 20 Awardees-Class of 2026

Initiative Highlights Extraordinary Young Leaders who are Making Meaningful Contributions to their Schools and

March 18, 2026

California’s New Auto Insurance Minimums Now in Effect: What Orange County Drivers Need to Know About 30/60/15 Coverage

California’s New Auto Insurance Minimums Now in Effect: What Orange County Drivers Need to Know About 30/60/15 Coverage

Irvine personal injury attorneys caution that many drivers remain underinsured despite higher state requirements

March 18, 2026

YogaFaith Launches the World’s First Christian, Bible-Based Sound Therapy Certification Program

YogaFaith Launches the World’s First Christian, Bible-Based Sound Therapy Certification Program

Seattle, WA, YOGAFAITH announces the launch of its groundbreaking Christian Sound Therapy Certification Program

March 18, 2026

SBC|Expert Construction Services Creates Florida Electrical Specialists to Meet Demand for Licensed, Code Compliant Work

SBC|Expert Construction Services Creates Florida Electrical Specialists to Meet Demand for Licensed, Code Compliant Work

Dedicated Electrical Contracting Company Provides Focused, Accountable Solution to Mitigate Complications and Safety

March 18, 2026

Simplain’s Growth Journey Continues with New Center of Excellence in Coimbatore

Simplain’s Growth Journey Continues with New Center of Excellence in Coimbatore

New facility strengthens Simplain’s engineering and technical capacity to enhance deliverability of innovative

March 18, 2026

Astroline Introduces Dedicated Ethics, Limits, and Disclaimers Section to Promote Responsible Use of Symbolic Frameworks

Astroline Introduces Dedicated Ethics, Limits, and Disclaimers Section to Promote Responsible Use of Symbolic Frameworks

Astroline adds Ethics & Disclaimers section to promote mindful, non-predictive use of symbolic self-exploration

March 18, 2026

TraineryHCM Wins Recognition for Best Innovative, Emerging Tech Solution in Talent Development

TraineryHCM Wins Recognition for Best Innovative, Emerging Tech Solution in Talent Development

The 2026 Lighthouse Tech Awards recognition reflects the strength of the TraineryLEARN solution and its differentiation

March 18, 2026

How Buyers Explore Homes Is Changing as Compass-Redfin and Keller Williams-Zillow Expand Focus on Search and Exposure

How Buyers Explore Homes Is Changing as Compass-Redfin and Keller Williams-Zillow Expand Focus on Search and Exposure

As industry partnerships emphasize listing visibility, The ReelMap introduces a discovery-based platform focused on how

March 18, 2026

Award-Winning Author Mona Liza Santos Honored by City & Community Leaders for Promoting Kindness and Emotional Literacy

Award-Winning Author Mona Liza Santos Honored by City & Community Leaders for Promoting Kindness and Emotional Literacy

Author Mona Liza Santos earns community recognition for championing kindness and emotional literacy through children’s

March 18, 2026

Factor’s Sensemaker Academy Named Winner for Best Tech Training Program at Legalweek

Factor’s Sensemaker Academy Named Winner for Best Tech Training Program at Legalweek

Recognition honors an AI training program that has helped 4,000 lawyers build practical legal AI capability. This

March 18, 2026

Denny LaVé Named One of IAOTP’S Top 50 Fearless Leaders

Denny LaVé Named One of IAOTP’S Top 50 Fearless Leaders

The International Association of Top Professionals (IAOTP) will honor Denny LaVé at their annual awards gala in NYC at

March 18, 2026

Apex Companies, LLC Acquires CWE

Apex Companies, LLC Acquires CWE

Complements service offerings with added strength in engineering capabilities in civil infrastructure, water resources

March 18, 2026

DiBooq Expands Its Vacation Rental Channel Manager with Seasonal and Global Booking Conditions

DiBooq Expands Its Vacation Rental Channel Manager with Seasonal and Global Booking Conditions

DiBooq expands its vacation rental channel manager with seasonal and global booking conditions, helping hosts manage

March 18, 2026

J Dubb Tha King Brings High-Energy Performance to Phoenix Alongside Yukmouth of The Luniz for Unforgettable Live Show

J Dubb Tha King Brings High-Energy Performance to Phoenix Alongside Yukmouth of The Luniz for Unforgettable Live Show

Blending Legacy and New Wave Energy in One Unforgettable Live Experience This show has been a long time coming. We want

March 18, 2026

Durham School Services’ Charli Sanders Wins Trailblazer Award for Leadership and Dedication to Student Transportation

Durham School Services’ Charli Sanders Wins Trailblazer Award for Leadership and Dedication to Student Transportation

I am grateful to work for leadership at Durham School Services that values the exploration of multiple ideas. Thank you

March 18, 2026

enQase Making Quantum Security Splash at RSA Conference 2026

enQase Making Quantum Security Splash at RSA Conference 2026

Platform innovations, thought leadership interviews, and industry engagement highlight enQase momentum in quantum-safe

March 18, 2026

SparrowDesk Launches Startup Program with Up to 90% Off on Enterprise Plan

SparrowDesk Launches Startup Program with Up to 90% Off on Enterprise Plan

SparrowDesk’s new startup program offers Startups its Enterprise plan to manage support end-to-end, powered by AI;

March 18, 2026

Telewave.io Launches Sentinel at IWCE 2026

Telewave.io Launches Sentinel at IWCE 2026

Turnkey private networks for mission-critical operations — LMR today, broadband-ready tomorrow, and AI now LAS VEGAS,

March 18, 2026

The State of TV 2026 Report Finds Streaming Dominates Viewing While Cable Retains Sports-Driven Staying Power

The State of TV 2026 Report Finds Streaming Dominates Viewing While Cable Retains Sports-Driven Staying Power

Jan 2026 CableTV.com survey of 1,000 U.S. adults: 92% streaming adoption, $30 avg streaming bill, $147 cable bill, with

March 18, 2026

Epoxy Floors NJ Announces Enhanced High-Performance Coating Solutions to Meet Growing Industrial Demand in New Jersey

Epoxy Floors NJ Announces Enhanced High-Performance Coating Solutions to Meet Growing Industrial Demand in New Jersey

Enhanced High-Performance Coating Solutions By optimizing our formulas for local environmental factors—like humidity

March 18, 2026