Malicious AI Agent Skills Turn OpenClaw Into Malware Delivery Platform

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Attackers exploited the OpenClaw AI agent platform by uploading hundreds of malicious skills to its ClawHub marketplace, causing the AI agents to download and execute malware, steal data, and compromise user security. Security firms and VirusTotal identified the widespread supply chain attack, prompting new automated scanning measures.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event explicitly involves AI systems (OpenClaw AI agent project and its AI plugins) and describes a direct harm caused by malicious AI plugins containing backdoors that steal sensitive data and enable extortion. The involvement of AI in the development and use of these plugins is clear, and the harm to users' data and security is realized, not just potential. Hence, it meets the criteria for an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Robustness & digital securityPrivacy & data governance

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
ConsumersBusiness

Harm types
Human or fundamental rights

Business function:
Other

AI system task:
Other

In other databases

Articles about this incident or hazard