Noti.Group RSS Feed
  • Contact Us
Sunday, April 5, 2026
Noti Group Logo
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment
No Result
View All Result
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment
No Result
View All Result
Noti Group
No Result
View All Result
ADVERTISEMENT

OpenClaw’s AI ‘skill’ extensions are a security nightmare

in Technology
Reading Time: 2 mins read
407 4
A A
0
OpenClaw’s AI ‘skill’ extensions are a security nightmare
137
SHARES
6.8k
VIEWS
ShareShareShareShareShare

OpenClaw, the AI agent that has exploded in popularity over the past week, is raising new security concerns after researchers uncovered malware in hundreds of user-submitted “skill” add-ons on its marketplace. In a post on Monday, 1Password product VP Jason Meller says OpenClaw’s skill hub has become “an attack surface,” with the most-downloaded add-on serving as a “malware delivery vehicle.”

OpenClaw — first called Clawdbot, then Moltbot — is billed as an AI agent that “actually does things,” such as managing your calendar, checking in for flights, cleaning out your inbox, and more. It runs locally on devices, and users can interact with the AI assistant through messaging apps like WhatsApp, Telegram, iMessage, and others. But some users are giving OpenClaw the ability to access their entire device, allowing it to read and write files, execute scripts, and run shell commands.

While this kind of access poses risks on its own, malware disguised as skills that are supposed to enhance OpenClaw’s capabilities only contribute to concerns. OpenSourceMalware, a platform that tracks the presence of malware across the open-source ecosystem, found that 28 malicious skills were published on the ClawHub skill marketplace between January 27th and 29th, in addition to 386 malicious add-ons that were uploaded between January 31st and February 2nd.

OpenSourceMalware says the skills “masquerade as cryptocurrency trading automation tools and deliver information-stealing malware” and manipulate users into executing malicious code that “steals crypto assets like exchange API keys, wallet private keys, SSH credentials, and browser passwords.”

Meller notes that OpenClaw’s skills are often uploaded as markdown files, which could contain malicious instructions for both users and the AI agent. That’s what he found when examining one of ClawHub’s most popular add-ons, a “Twitter” skill containing instructions for users to navigate to a link “designed to get the agent to run a command” that downloads infostealing malware.

OpenClaw’s creator, Peter Steinberger, is working to address some of these risks, as ClawHub now requires users to have a GitHub account that’s at least one week old to publish a skill. There’s also a new way to report skills, though this doesn’t remove the possibility of malware sneaking onto the platform.

[Notigroup Newsroom in collaboration with other media outlets, with information from the following sources]

Tags: AINewssecurityTech
Previous Post

I was detained by federal agents in Minneapolis

Next Post

Bahama Breeze to close all its restaurants

Related Posts

Terrence O'Brien
Technology

Suno is a music copyright nightmare capable of pumping out AI cover slop

April 5, 2026
I let Gemini in Google Maps plan my day and it went surprisingly well
Technology

I let Gemini in Google Maps plan my day and it went surprisingly well

April 5, 2026
Is the Slate Truck too minimal for its own good?
Technology

Is the Slate Truck too minimal for its own good?

April 5, 2026
The full origins of Alexa and the Amazon Echo
Technology

The full origins of Alexa and the Amazon Echo

April 5, 2026
Load More
Next Post
The Bahama Breeze Island Grille sign on the front of the restaurant building.

Bahama Breeze to close all its restaurants

No Result
View All Result

Recent Posts

  • UFC legend Jon Jones in heated road rage confrontation
  • How to watch Rangers vs. Capitals in NHL ‘Inside Out Classic’
  • Nationals fan born on day of team’s first game takes ceremonial ‘first sip’ on 21st birthday
  • Los Thuthanaka Wak’a review | noti.group
  • Get a 20% first deposit match up to $1,500 for South Carolina vs. UCLA

Recent Comments

  • Stefano on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Van Hens on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Ioannis K on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Panagiotis Nikolaos on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • John Miele on UK government suggests deleting files to save water

Noti Group All rights reserved

No Result
View All Result
Noti Group

What’s New Here

  • UFC legend Jon Jones in heated road rage confrontation
  • How to watch Rangers vs. Capitals in NHL ‘Inside Out Classic’
  • Nationals fan born on day of team’s first game takes ceremonial ‘first sip’ on 21st birthday

Topics to Cover!

  • Business (4,804)
  • Entertainment (1,911)
  • General News (326)
  • Health (327)
  • Investigative Journalism (12)
  • Lifestyle (4)
  • Sports (8,976)
  • Technology (6,363)
  • World News (1,336)
  • Contact Us
  • Terms and Conditions
  • Privacy Policy
  • RSS
  • Contact News Room
  • Code of Conduct
  • Careers
  • Values
  • Advertise
  • DMCA

© 2025 - noti.group - All rights reserved - noti.group runs on 100% green energy.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment

© 2025 - noti.group - All rights reserved - noti.group runs on 100% green energy.