This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Tabuga Think Tank presents its first report Perspectives on digitalization of the Dominican Republic

Tabuga Think Tank presents its first report Perspectives on digitalization of the Dominican Republic

The report was developed from interviews with leaders of the national technology ecosystem. SANTO DOMINGO, DN,

March 17, 2026

Students Turn Raw News Data Into Visual Stories at 2026 Newsmatics Hackathon in Brno

Students Turn Raw News Data Into Visual Stories at 2026 Newsmatics Hackathon in Brno

High school, undergraduate and graduate students competed over 24 hours to analyze news trends, forecast future cycles,

March 17, 2026

Your Doctors Online Reports Serving More Than 1 Million Patients Through Its Virtual Healthcare Platform

Your Doctors Online Reports Serving More Than 1 Million Patients Through Its Virtual Healthcare Platform

Your Doctors Online says its telehealth platform has now served more than one million patients, reflecting growing

March 17, 2026

Author Michaele Aldophe Announces New Romantic Novel ‘Still, I Remember You’

Author Michaele Aldophe Announces New Romantic Novel ‘Still, I Remember You’

A heartfelt story of love, distance, and destiny set between the romantic streets of Paris and the breathtaking shores

March 17, 2026

Why Patients Are Traveling to Playa del Carmen for Veneers and Cosmetic Dentistry in Mexico

Why Patients Are Traveling to Playa del Carmen for Veneers and Cosmetic Dentistry in Mexico

A1 Smile Design explains the types of dental veneers available in Mexico, their benefits, and why Playa del Carmen is a

March 17, 2026

Marcus Jordan Announced as 2026 Recording Artist of the Year Award

Marcus Jordan Announced as 2026 Recording Artist of the Year Award

The Gospel Artist Celebrates Award Win With New Music Announcement LOS ANGELES, CA, UNITED STATES, March 17, 2026

March 17, 2026

InSkin Laser Aesthetics Introduces the Matrix® Skin Renewal Platform: A Revolutionary Approach to Skin Health

InSkin Laser Aesthetics Introduces the Matrix® Skin Renewal Platform: A Revolutionary Approach to Skin Health

At InSkin Laser Aesthetics, our goal has always been to provide treatments that deliver real, visible results while

March 17, 2026

AUVSI CEO Testifies on Risks of Chinese Robotics and AI

AUVSI CEO Testifies on Risks of Chinese Robotics and AI

Securing America’s leadership in robotics will require both carrots and sticks.”— AUVSI President & CEO Michael

March 17, 2026

The Mahdavi Law Firm Launches Personal Injury Claims Quiz for Texans

The Mahdavi Law Firm Launches Personal Injury Claims Quiz for Texans

The Mahdavi Law Firm PLLC Announces the Launch of Its Personal Injury Claims Quiz, Giving Texans a New Way To Evaluate

March 17, 2026

SYDNEY BASED BLOG CHICKS LIFESTYLE MAGAZINE COMMENCE FEATURES ON AN ARRAY OF MOBILE PHONE RELATED MATTERS

SYDNEY BASED BLOG CHICKS LIFESTYLE MAGAZINE COMMENCE FEATURES ON AN ARRAY OF MOBILE PHONE RELATED MATTERS

Management of Blog Chicks confirmed to Metro Cities Media they will commence monthly feature posts in March ranging

March 17, 2026

Introducing the Agentic Marketing Mastermind for Agency Owners

Introducing the Agentic Marketing Mastermind for Agency Owners

Elevate Your Marketing Game with the Agentic Marketing Mastermind New York, United States – March 17, 2026 / Search

March 17, 2026

Kilgore, Texas Series Debuts on ‘Gone to Texas’ Business Podcast Highlighting East Texas Manufacturing

Kilgore, Texas Series Debuts on ‘Gone to Texas’ Business Podcast Highlighting East Texas Manufacturing

Company leaders share stories of workforce strength, industrial readiness, and business growth in East Texas. Kilgore’s

March 17, 2026

EPC Group Launches AI Decision Intelligence Framework for Microsoft Power BI

EPC Group Launches AI Decision Intelligence Framework for Microsoft Power BI

New framework combines Copilot, Claude, ChatGPT, Gemini, Perplexity, and multi-model LLMs to transform Power BI and

March 17, 2026

MRC Rocket Inc Launches Full-Service Digital Marketing Agency for E-Commerce and Small Businesses

MRC Rocket Inc Launches Full-Service Digital Marketing Agency for E-Commerce and Small Businesses

MRC Rocket Inc launches digital marketing services including SEO, PPC, social media, and content strategy for

March 17, 2026

6 Reasons Why Today’s Construction Labor Environment Will Likely Increase Disputes & Litigation In 2026

6 Reasons Why Today’s Construction Labor Environment Will Likely Increase Disputes & Litigation In 2026

Fundamental changes in the U.S. construction labor market have occurred affecting costs, availability, capabilities and

March 17, 2026

Dr. Renee Thompson Announced as a Pre-Conference Speaker at the 2026 AONL Annual Conference in Chicago

Dr. Renee Thompson Announced as a Pre-Conference Speaker at the 2026 AONL Annual Conference in Chicago

Creating a healthy work culture doesn’t happen by chance, It happens when leaders are equipped to address behavior, set

March 17, 2026

LET’S TALK WOMXN CHICAGO PRESENTS THEIR SIXTH ANNUAL WOMEN’S HISTORY MONTH CELEBRATION ‘RETRO REVOLUTION DANCE PARTY’

LET’S TALK WOMXN CHICAGO PRESENTS THEIR SIXTH ANNUAL WOMEN’S HISTORY MONTH CELEBRATION ‘RETRO REVOLUTION DANCE PARTY’

Spend the evening in an unabashed celebration of women empowering women; this celebration is for all of Chicago

March 17, 2026

The Book of Revelation: Revealing the Salvation of God by Hegumen Abraam Sleman Now Available

The Book of Revelation: Revealing the Salvation of God by Hegumen Abraam Sleman Now Available

A Gospel-centered interpretation of Revelation revealing God’s salvation, Christ’s victory, and hope The Book of

March 17, 2026

Palm Beach Tan Tyler Expands Into Wellness With Red Light Therapy and Infrared Sauna Services

Palm Beach Tan Tyler Expands Into Wellness With Red Light Therapy and Infrared Sauna Services

Tyler location adds Red Light Therapy and Infrared Sauna to complement its premier tanning services TYLER, TX, UNITED

March 17, 2026

Injury Care Solutions Group: A Well-Known Wide Receiver and the Lisfranc Injury Explained

Injury Care Solutions Group: A Well-Known Wide Receiver and the Lisfranc Injury Explained

Dr. Greg Vigna highlights wide receiver's resilience after injury and underscores the value of evidence-based expert

March 17, 2026

Turf Distributors Expands Fulfillment with Strategic Transition of Cut & Deliver Operations to Ewing Outdoor Supply

Turf Distributors Expands Fulfillment with Strategic Transition of Cut & Deliver Operations to Ewing Outdoor Supply

Partnership Strengthens Nationwide Distribution, Enhances Contractor Access to Premium Turf Products Transitioning our

March 17, 2026

Muse Treatment Alcohol & Drug Rehab Los Angeles Publishes Critical New Resource on Website Examining Withdrawal Treatment for Xylazine-Linked “Zombie Drug” Exposure

Muse Treatment Alcohol & Drug Rehab Los Angeles Publishes Critical New Resource on Website Examining Withdrawal Treatment for Xylazine-Linked “Zombie Drug” Exposure

LOS ANGELES, CA – March 17, 2026 – PRESSADVANTAGE – Muse Treatment Alcohol & Drug Rehab Los Angeles has released a comprehensive new educational resource…

March 17, 2026

Now Available: New Leadership Book No Shortcuts: What It Really Takes Confronts the Problem of Leadership Drift

Now Available: New Leadership Book No Shortcuts: What It Really Takes Confronts the Problem of Leadership Drift

Released during National Ethics Month, the book is already drawing attention from business leaders across industries.

March 17, 2026

McCarthy & Akers, PLC Sharpens Its Sole Focus on Estate Planning

McCarthy & Akers, PLC Sharpens Its Sole Focus on Estate Planning

McCarthy & Akers Announces Its Exclusive Focus on Estate Planning, Dedicating Full Attention to Holistic,

March 17, 2026

SPARK ’26 Brings Together Tamil Tech Entrepreneurs, Investors, Industry Leaders for a National Innovation Summit in NJ

SPARK ’26 Brings Together Tamil Tech Entrepreneurs, Investors, Industry Leaders for a National Innovation Summit in NJ

SPARK represents the energy and momentum of Tamil entrepreneurs in the technology sector,”— representatives from the

March 17, 2026

SAF Win: Post Office Carry Ban Injunction Covers Current and Future Members

SAF Win: Post Office Carry Ban Injunction Covers Current and Future Members

SAF Win: Post Office Carry Ban Injunction Covers Current and Future Members This is a huge win for current and future

March 17, 2026

Broadway Welcomes a New Wave of Shows as the World Cup Draws Worldwide Visitors

Broadway Welcomes a New Wave of Shows as the World Cup Draws Worldwide Visitors

NEW YORK, NY, UNITED STATES, March 17, 2026 /EINPresswire.com/ — As the NYC area prepares to host soccer fans during

March 17, 2026

AGPROfessionals Founder Tom Haren Named a 2026 ‘Leader in Agriculture’ by Denver Business Journal

AGPROfessionals Founder Tom Haren Named a 2026 ‘Leader in Agriculture’ by Denver Business Journal

GREELEY, CO, UNITED STATES, March 17, 2026 /EINPresswire.com/ — AGPROfessionals proudly announces that Founder and CEO

March 17, 2026

BaRupOn Healthcare Strengthens U.S. Medical Infrastructure

BaRupOn Healthcare Strengthens U.S. Medical Infrastructure

BaRupOn Healthcare integrates pharmacy, distribution, and biomedical innovation to strengthen U.S. healthcare supply

March 17, 2026

Aesthetic Expert Linda Rank Featured at VIP Oscars Gifting Lounge in Beverly Hills

Aesthetic Expert Linda Rank Featured at VIP Oscars Gifting Lounge in Beverly Hills

VIP Beverly Hills gifting lounge featured national trainer Linda Rank of Orange County, known for natural results and

March 17, 2026

Network Strategics Launches New AI Chat Agent Integration Service

Network Strategics Launches New AI Chat Agent Integration Service

New AI agent helps enhance lead qualification, supports instant responses, and integrates seamlessly at competitive

March 17, 2026

Amana Care Clinic Announces Enhanced Walk-In Medical Services Across Quad Cities Region

Amana Care Clinic Announces Enhanced Walk-In Medical Services Across Quad Cities Region

DAVENPORT, Iowa – March 17, 2026 – PRESSADVANTAGE – Amana Care Clinic has announced enhanced walk-in medical services

March 17, 2026

El consorcio MANTA selecciona a MDC Data Centers como socio neutral para el aterrizaje de su cable submarino en México

El consorcio MANTA selecciona a MDC Data Centers como socio neutral para el aterrizaje de su cable submarino en México

Liberty Networks, Gold Data y Sparkle aterrizarán el cable submarino MANTA en Cancún y Veracruz a través de centros de interconexión neutral de MDC Data…

March 17, 2026

Lutsen Mountains named a winner in Midwest Living’s 2026 Best of the Midwest Awards

Lutsen Mountains named a winner in Midwest Living’s 2026 Best of the Midwest Awards

North Shore resort recognized as one of the region’s top travel destinations LUTSEN, MN, UNITED STATES, March 17, 2026

March 17, 2026

Esomar announces the programme for its Asia Pacific 2026 conference in Tokyo

Esomar announces the programme for its Asia Pacific 2026 conference in Tokyo

The three-day event, 27–29 May 2026, features global brands, AI in practice and standout networking designed to spark

March 17, 2026

LeVar Pompey Featured on Next Level CEO

LeVar Pompey Featured on Next Level CEO

FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Rev. LeVar Pompey, founder of DOMINION LIVING PROPERTIES LLC,

March 17, 2026

Ricardo Regalado Featured on Next Level CEO

Ricardo Regalado Featured on Next Level CEO

FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Ricardo Regalado, founder of Route/Rozalado/Cleaning &

March 17, 2026

The Colliding AI-Energy-Carbon Management Trilemma in the Age of Physical and Digital Infrastructure

The Colliding AI-Energy-Carbon Management Trilemma in the Age of Physical and Digital Infrastructure

At the 2026 American Data Centers Forum, SFLCT brings a frontline low-carbon energy systems perspective as compute

March 17, 2026

LISA RINNA OPENS UP ABOUT BULLYING, FAITH, PROTECTING HER DAUGHTERS FROM SOCIAL MEDIA

LISA RINNA OPENS UP ABOUT BULLYING, FAITH, PROTECTING HER DAUGHTERS FROM SOCIAL MEDIA

Lisa Rinna, (Real Housewives of Beverly Hills) appeared on the YouTube show Books That Changed My Life to talk

March 17, 2026

Image Analysis Group Achieves SOC 2 Type II Certification, Setting the Enterprise Benchmark for Global Imaging CROs

Image Analysis Group Achieves SOC 2 Type II Certification, Setting the Enterprise Benchmark for Global Imaging CROs

DYNAMIKA™ delivers SOC 2 Type II–certified, AI‑driven imaging workflows, giving pharma and biotech secure, compliant

March 17, 2026