Noti.Group RSS Feed
  • Contact Us
Saturday, May 16, 2026
Noti Group Logo
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment
No Result
View All Result
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment
No Result
View All Result
Noti Group
No Result
View All Result
ADVERTISEMENT

OpenClaw’s AI ‘skill’ extensions are a security nightmare

in Technology
Reading Time: 2 mins read
407 4
A A
0
OpenClaw’s AI ‘skill’ extensions are a security nightmare
137
SHARES
6.8k
VIEWS
ShareShareShareShareShare

OpenClaw, the AI agent that has exploded in popularity over the past week, is raising new security concerns after researchers uncovered malware in hundreds of user-submitted “skill” add-ons on its marketplace. In a post on Monday, 1Password product VP Jason Meller says OpenClaw’s skill hub has become “an attack surface,” with the most-downloaded add-on serving as a “malware delivery vehicle.”

OpenClaw — first called Clawdbot, then Moltbot — is billed as an AI agent that “actually does things,” such as managing your calendar, checking in for flights, cleaning out your inbox, and more. It runs locally on devices, and users can interact with the AI assistant through messaging apps like WhatsApp, Telegram, iMessage, and others. But some users are giving OpenClaw the ability to access their entire device, allowing it to read and write files, execute scripts, and run shell commands.

While this kind of access poses risks on its own, malware disguised as skills that are supposed to enhance OpenClaw’s capabilities only contribute to concerns. OpenSourceMalware, a platform that tracks the presence of malware across the open-source ecosystem, found that 28 malicious skills were published on the ClawHub skill marketplace between January 27th and 29th, in addition to 386 malicious add-ons that were uploaded between January 31st and February 2nd.

OpenSourceMalware says the skills “masquerade as cryptocurrency trading automation tools and deliver information-stealing malware” and manipulate users into executing malicious code that “steals crypto assets like exchange API keys, wallet private keys, SSH credentials, and browser passwords.”

Meller notes that OpenClaw’s skills are often uploaded as markdown files, which could contain malicious instructions for both users and the AI agent. That’s what he found when examining one of ClawHub’s most popular add-ons, a “Twitter” skill containing instructions for users to navigate to a link “designed to get the agent to run a command” that downloads infostealing malware.

OpenClaw’s creator, Peter Steinberger, is working to address some of these risks, as ClawHub now requires users to have a GitHub account that’s at least one week old to publish a skill. There’s also a new way to report skills, though this doesn’t remove the possibility of malware sneaking onto the platform.

[Notigroup Newsroom in collaboration with other media outlets, with information from the following sources]

Tags: AINewssecurityTech
Previous Post

I was detained by federal agents in Minneapolis

Next Post

Bahama Breeze to close all its restaurants

Related Posts

Social media on trial: tech giants face lawsuits over addiction, safety, and mental health
Technology

Snap, YouTube, and TikTok settle suit over harm to students

May 16, 2026
Sony tries to explain that its AI Camera Assistant doesn’t suck
Technology

Sony tries to explain that its AI Camera Assistant doesn’t suck

May 16, 2026
Turtle Beach made a good SteelSeries headset clone that’s $50 less
Technology

Turtle Beach made a good SteelSeries headset clone that’s $50 less

May 16, 2026
Here are 40 of our favorite deals from REI’s massive Anniversary Sale
Technology

Here are 40 of our favorite deals from REI’s massive Anniversary Sale

May 16, 2026
Load More
Next Post
The Bahama Breeze Island Grille sign on the front of the restaurant building.

Bahama Breeze to close all its restaurants

No Result
View All Result

Recent Posts

  • Yankees vs. Mets prediction: Subway Series picks, odds for Saturday
  • Rare Aaron Judge baseball card sells for close to $1 million at auction
  • Snap, YouTube, and TikTok settle suit over harm to students
  • Minor league teams clash in benches-clearing brawl
  • Newest sports trivia game’s geography twist makes it addictive

Recent Comments

  • Stefano on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Van Hens on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Ioannis K on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Panagiotis Nikolaos on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • John Miele on UK government suggests deleting files to save water

Noti Group All rights reserved

No Result
View All Result
Noti Group

What’s New Here

  • Yankees vs. Mets prediction: Subway Series picks, odds for Saturday
  • Rare Aaron Judge baseball card sells for close to $1 million at auction
  • Snap, YouTube, and TikTok settle suit over harm to students

Topics to Cover!

  • Business (4,948)
  • Entertainment (2,012)
  • General News (326)
  • Health (327)
  • Investigative Journalism (12)
  • Lifestyle (4)
  • Sports (10,623)
  • Technology (6,987)
  • World News (1,336)
  • Contact Us
  • Terms and Conditions
  • Privacy Policy
  • RSS
  • Contact News Room
  • Code of Conduct
  • Careers
  • Values
  • Advertise
  • DMCA

© 2025 - noti.group - All rights reserved - noti.group runs on 100% green energy.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment

© 2025 - noti.group - All rights reserved - noti.group runs on 100% green energy.