This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Sisters of the Valley Announce Next Stops on Their Statewide Tour

Sisters of the Valley Announce Next Stops on Their Statewide Tour

Pursuing Their Mission to Meet Every Staff Member at Every Catalyst and Traditional Dispensary in California MERCED, CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ —…

March 18, 2026

The Future of Aesthetic Practices Starts Here: Pink Sky and Fifth & Cor Announce Strategic Partnership

The Future of Aesthetic Practices Starts Here: Pink Sky and Fifth & Cor Announce Strategic Partnership

From operational systems to immersive marketing, the partnership helps practices stop repeating outdated playbooks and start building the future. The future of aesthetic practices will…

March 18, 2026

Converge @ SXSW Brings Creators, Brands, and Media Together for a Standing-Room-Only Gathering at Soho House Austin

Converge @ SXSW Brings Creators, Brands, and Media Together for a Standing-Room-Only Gathering at Soho House Austin

One of SXSW’s most talked-about gatherings unites the leaders shaping the future of media, brands, and creator-led

March 18, 2026

Suplari Launches Spend Analytics for the AI Era

Suplari Launches Spend Analytics for the AI Era

Solution delivers actionable procurement intelligence from day one backed by nine years of AI investment and a data

March 18, 2026

NanoGas Cuts Lagoon Sludge 83%, Showcasing Breakthrough Wastewater Tech for $600B U.S. Market

NanoGas Cuts Lagoon Sludge 83%, Showcasing Breakthrough Wastewater Tech for $600B U.S. Market

Proven nanobubble technology restores wastewater lagoons faster and cheaper, unlocking scalable infrastructure

March 18, 2026

CanAm Enterprises Releases 2025 PKF-Attested EB-5 Track Record, Reporting $2.5 Billion Repaid and 5,797 I-526 Approvals

CanAm Enterprises Releases 2025 PKF-Attested EB-5 Track Record, Reporting $2.5 Billion Repaid and 5,797 I-526 Approvals

Independent attestation by PKF O'Connor Davies, LLP marks the company's seventh consecutive year of third-party

March 18, 2026

Netlify Turns AI Prompts Into Production-Ready Software

Netlify Turns AI Prompts Into Production-Ready Software

It’s not enough to help a builder get something live quickly. You have to give them a real project on infrastructure

March 18, 2026

Taste of Richmond Experience Set for March 28 at Richmond Memorial Auditorium

Taste of Richmond Experience Set for March 28 at Richmond Memorial Auditorium

40 Food & Beverage Vendors to Gather for Ticketed Community Tasting Event We’re seeing strong momentum from across

March 18, 2026

Out of Africa Wildlife Park & Sanctuary Voted a Top 10 Safari Park in USA TODAY’s 2026 10Best Awards

Out of Africa Wildlife Park & Sanctuary Voted a Top 10 Safari Park in USA TODAY’s 2026 10Best Awards

Camp Verde wildlife destination earns national recognition in the 2026 USA TODAY 10Best Readers’ Choice Awards This

March 18, 2026

40-Year Building Recertification Deadlines Announced in Miami-Dade

40-Year Building Recertification Deadlines Announced in Miami-Dade

The firm offers structural and electrical evaluations aligned with 40-year building recertification in Miami-Dade

March 18, 2026

Cambashi’s View: the Mechanical CAE Market in 2025 and Opportunities for 2026

Cambashi’s View: the Mechanical CAE Market in 2025 and Opportunities for 2026

Cambashi reviews the mechanical CAE and simulation market, highlighting AI innovation, major acquisitions, and growth

March 18, 2026

Mechael Sisters Appointed Ambassadors for Peace by the Universal Peace Federation in Affiliation with the United Nations

Mechael Sisters Appointed Ambassadors for Peace by the Universal Peace Federation in Affiliation with the United Nations

Sisters Farrah and Tamara Mechael have been formally appointed as Ambassadors for Peace by the Universal Peace

March 18, 2026

Quechan Casino Resort Welcomes Los Tigres del Norte On Saturday May 9th

Quechan Casino Resort Welcomes Los Tigres del Norte On Saturday May 9th

WINTERHAVEN, CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Quechan Casino Resort is proud to welcome Los

March 18, 2026

‘Discovering High School Cross Country : Going the Extra Mile’ by Coach Kyle Rankin

‘Discovering High School Cross Country : Going the Extra Mile’ by Coach Kyle Rankin

A comprehensive guide for young distance runners, "Discovering High School Cross Country" provides insights and

March 18, 2026

Boosteroid Deploys Additional Cloud Gaming Server Capacity to Support Growing Player Base

Boosteroid Deploys Additional Cloud Gaming Server Capacity to Support Growing Player Base

AUSTIN, TX, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Boosteroid has deployed additional capacity in France,

March 18, 2026

Smart microspheres clean hospital wastewater on two fronts

Smart microspheres clean hospital wastewater on two fronts

GA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Hospital wastewater is difficult to clean because it often

March 18, 2026

National Animation Museum Commended by Southern California Elected Officials

National Animation Museum Commended by Southern California Elected Officials

Elected officials honor the museum’s progress and contributions to the region. BURBANK, CA, UNITED STATES, March 18,

March 18, 2026

Sasso Guerrero & Henderlite Expands Online Media Center for Family Law Resources

Sasso Guerrero & Henderlite Expands Online Media Center for Family Law Resources

JACKSONVILLE, FL – March 18, 2026 – PRESSADVANTAGE – Sasso Guerrero & Henderlite, a Jacksonville-based family and

March 18, 2026

Ornate Home Expands Sleep Solutions with Malouf Furniture and Mattress Collection

Ornate Home Expands Sleep Solutions with Malouf Furniture and Mattress Collection

SANTA ANA, CA – March 18, 2026 – PRESSADVANTAGE – Ornate Home, a Southern California-based retailer specializing in

March 18, 2026

Stor-Mor 135 Self Storage Announces Enhanced Brand Identity and Expanded Services Release

Stor-Mor 135 Self Storage Announces Enhanced Brand Identity and Expanded Services Release

PARK CITY, KS – March 18, 2026 – PRESSADVANTAGE – Stor-Mor 135 Self Storage, operated by Eden's Property Management LLC

March 18, 2026

Soraban Appoints Steven Lopez as Vice President of Customer Experience to Scale Firm Capacity Nationwide

Soraban Appoints Steven Lopez as Vice President of Customer Experience to Scale Firm Capacity Nationwide

SAN FRANCISCO, CA – March 18, 2026 – PRESSADVANTAGE – Soraban, the intelligent tax workflow execution layer helping

March 18, 2026

Tiles Workshop LLC Announces New Permanent Mosaic Lamp Workshop Studios Opening in Dallas and St. Louis

Tiles Workshop LLC Announces New Permanent Mosaic Lamp Workshop Studios Opening in Dallas and St. Louis

Dallas, TX – March 18, 2026 – PRESSADVANTAGE – Tiles Workshop LLC, a creative experiences company specializing in

March 18, 2026

Heritage Signs & Displays Opens New Charlotte Headquarters on Yorkmont Road

Heritage Signs & Displays Opens New Charlotte Headquarters on Yorkmont Road

CHARLOTTE, NC – March 18, 2026 – PRESSADVANTAGE – The 4-Acre Charlotte Campus Will Serve as HQ and Regional Production

March 18, 2026

Pennsylvania Parks and Forests Foundation Announces 2026 Award Winners; Registration Now Open for May 12 Celebration

Pennsylvania Parks and Forests Foundation Announces 2026 Award Winners; Registration Now Open for May 12 Celebration

CAMP HILL, PA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — The Pennsylvania Parks and Forests Foundation (PPFF)

March 18, 2026

Protagonist Therapeutics Announces U.S. FDA Approval of ICOTYDE(TM) (icotrokinra) for the Treatment of Moderate to Severe Plaque Psoriasis

Protagonist Therapeutics Announces U.S. FDA Approval of ICOTYDE(TM) (icotrokinra) for the Treatment of Moderate to Severe Plaque Psoriasis

ICOTYDE is the first and only IL-23R targeted oral peptide that delivers complete skin clearance and a favorable safety profile in a once-daily pill Approval…

March 18, 2026

Goodguys 42nd All American Get-Together Brings Customs, Classic Trucks, Modern Muscle Cars and more to the Bay Area

Goodguys 42nd All American Get-Together Brings Customs, Classic Trucks, Modern Muscle Cars and more to the Bay Area

Goodguys Rod & Custom Association is bringing custom cars, lowriders, modern muscle machines and classic trucks to

March 18, 2026

Renewables Opens Follow-On Investment Round Through Highlander AI as e2T Electric Tractor Enters Field Deployment

Renewables Opens Follow-On Investment Round Through Highlander AI as e2T Electric Tractor Enters Field Deployment

Early demand is confirmed, pilots are underway, and the next 50 units are in production. Highlander AI investors join

March 18, 2026

Texas Phone-Free Schools HB 1481 Is Law — The NuKase Gives Districts a Bell-To-Bell Solution

Texas Phone-Free Schools HB 1481 Is Law — The NuKase Gives Districts a Bell-To-Bell Solution

$20 Million in Texas Grant Funding Expires August 31 — Districts That Haven't Deployed a Phone-Free Classroom Solution

March 18, 2026

Senior Justice Law Firm Expands Litigation Team with Attorneys Michael Del Sontro and Samantha Harris

Senior Justice Law Firm Expands Litigation Team with Attorneys Michael Del Sontro and Samantha Harris

Experienced trial attorneys join national nursing home abuse and medical malpractice litigation firm As our firm

March 18, 2026

EVOX IMAGES PROMOTES GINA CALLARI TO PRESIDENT AND CHIEF OPERATING OFFICER

EVOX IMAGES PROMOTES GINA CALLARI TO PRESIDENT AND CHIEF OPERATING OFFICER

I look forward to working with our clients and partners to solve for the needs of tomorrow’s car shoppers and deliver

March 18, 2026

Rentex Launches New Website for AV and Live Event Professionals

Rentex Launches New Website for AV and Live Event Professionals

Rentex, a leading provider of professional AV rental equipment, today announced the launch of its newly redesigned

March 18, 2026

Fisher College in Boston Ranks Among the Nation’s Best in Digital Advertising Awards

Fisher College in Boston Ranks Among the Nation’s Best in Digital Advertising Awards

Fisher College Boston ranks among the nation’s best in the Digital Advertising Awards, recognized for excellence in

March 18, 2026

Tenovi Ranked No. 1 on The Boston Globe’s list of New England’s Fastest Growing Companies 2026

Tenovi Ranked No. 1 on The Boston Globe’s list of New England’s Fastest Growing Companies 2026

Based on the results of the study, Tenovi is honored to be recognized as No. 1 on The Boston Globe’s list of New

March 18, 2026

Marina St Barth Provides the Passport for Resort Chic from Palm Beach to Southampton

Marina St Barth Provides the Passport for Resort Chic from Palm Beach to Southampton

Celebrating Two Decades of Style and Elegance in March 2026 NEW YORK, NY, UNITED STATES, March 18, 2026

March 18, 2026

New INTOO/Harris Poll Study Reveals Innovation Paradox in the American Workplace

New INTOO/Harris Poll Study Reveals Innovation Paradox in the American Workplace

Employees Are Expected to Innovate — Yet 41% Fear Being Fired for Making a Mistake LOS ANGELES, CA, UNITED STATES,

March 18, 2026

Haugen Academy Expands Education Portfolio with Clinical Documentation Integrity (CDI) Training

Haugen Academy Expands Education Portfolio with Clinical Documentation Integrity (CDI) Training

New CDI-specific education helps align clinical indicators, provider documentation, and compliant coding practices.

March 18, 2026

FDA Grants NeuroGenesis Bio RMAT Designation for NG01 for Treatment of Secondary Progressive Multiple Sclerosis

FDA Grants NeuroGenesis Bio RMAT Designation for NG01 for Treatment of Secondary Progressive Multiple Sclerosis

RMAT designation is based on promising Phase 2 clinical data demonstrating NG01’s potential to reduce disability and

March 18, 2026

Austin Trauma Therapy Center Expands to Chicago and Las Vegas

Austin Trauma Therapy Center Expands to Chicago and Las Vegas

Austin Trauma Therapy Center expands trauma services to Chicago and Las Vegas, providing evidence-based mental health

March 18, 2026

Jack Black gives Minecraft Fan Surprise of a Lifetime from Kids Wish Network

Jack Black gives Minecraft Fan Surprise of a Lifetime from Kids Wish Network

7-year-old David from Ohio is surprised by Jack Black during a Kids Wish Network virtual wish inspired by his love of

March 18, 2026

Committed to Capital Expands Business Funding Comparison Support for U.S. Small Businesses

Committed to Capital Expands Business Funding Comparison Support for U.S. Small Businesses

Pitman, New Jersey firm helps owners review lender options and repayment structures beyond traditional banks Access to

March 18, 2026