Noti.Group RSS Feed
  • Contact Us
Friday, June 26, 2026
Noti Group Logo
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment
No Result
View All Result
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment
No Result
View All Result
Noti Group
No Result
View All Result
ADVERTISEMENT

OpenClaw’s AI ‘skill’ extensions are a security nightmare

in Technology
Reading Time: 2 mins read
407 4
A A
0
OpenClaw’s AI ‘skill’ extensions are a security nightmare
137
SHARES
6.9k
VIEWS
ShareShareShareShareShare

OpenClaw, the AI agent that has exploded in popularity over the past week, is raising new security concerns after researchers uncovered malware in hundreds of user-submitted “skill” add-ons on its marketplace. In a post on Monday, 1Password product VP Jason Meller says OpenClaw’s skill hub has become “an attack surface,” with the most-downloaded add-on serving as a “malware delivery vehicle.”

OpenClaw — first called Clawdbot, then Moltbot — is billed as an AI agent that “actually does things,” such as managing your calendar, checking in for flights, cleaning out your inbox, and more. It runs locally on devices, and users can interact with the AI assistant through messaging apps like WhatsApp, Telegram, iMessage, and others. But some users are giving OpenClaw the ability to access their entire device, allowing it to read and write files, execute scripts, and run shell commands.

While this kind of access poses risks on its own, malware disguised as skills that are supposed to enhance OpenClaw’s capabilities only contribute to concerns. OpenSourceMalware, a platform that tracks the presence of malware across the open-source ecosystem, found that 28 malicious skills were published on the ClawHub skill marketplace between January 27th and 29th, in addition to 386 malicious add-ons that were uploaded between January 31st and February 2nd.

OpenSourceMalware says the skills “masquerade as cryptocurrency trading automation tools and deliver information-stealing malware” and manipulate users into executing malicious code that “steals crypto assets like exchange API keys, wallet private keys, SSH credentials, and browser passwords.”

Meller notes that OpenClaw’s skills are often uploaded as markdown files, which could contain malicious instructions for both users and the AI agent. That’s what he found when examining one of ClawHub’s most popular add-ons, a “Twitter” skill containing instructions for users to navigate to a link “designed to get the agent to run a command” that downloads infostealing malware.

OpenClaw’s creator, Peter Steinberger, is working to address some of these risks, as ClawHub now requires users to have a GitHub account that’s at least one week old to publish a skill. There’s also a new way to report skills, though this doesn’t remove the possibility of malware sneaking onto the platform.

[Notigroup Newsroom in collaboration with other media outlets, with information from the following sources]

Tags: AINewssecurityTech
Previous Post

I was detained by federal agents in Minneapolis

Next Post

Bahama Breeze to close all its restaurants

Related Posts

RAMageddon just got extremely real
Technology

RAMageddon just got extremely real

June 26, 2026
OpenAI just released its answer to Claude Mythos
Technology

OpenAI will delay GPT-5.6 after Trump administration request

June 25, 2026
Android 17’s new foldable gaming mode could make flippy phones more fun
Technology

Android 17’s new foldable gaming mode could make flippy phones more fun

June 25, 2026
YouTube updates Shorts to make it even more like TikTok
Technology

YouTube updates Shorts to make it even more like TikTok

June 25, 2026
Load More
Next Post
The Bahama Breeze Island Grille sign on the front of the restaurant building.

Bahama Breeze to close all its restaurants

No Result
View All Result

Recent Posts

  • The stupidity in sports is reaching insulting levels
  • Marina Mabrey ties WNBA record for most points in a game
  • David Peterson serves as ‘tough’ Mets casualty as trade deadline looms
  • Mitchell Robinson unlikely to return to Knicks as team faces second apron crunch
  • Juan Soto returns to Mets lineup after back issue in ‘good sign’

Recent Comments

  • Stefano on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Van Hens on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Ioannis K on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • Panagiotis Nikolaos on The Last Byzantine Medieval Town on Earth Is Being Destroyed, and It’s Too Late
  • John Miele on UK government suggests deleting files to save water

Noti Group All rights reserved

No Result
View All Result
Noti Group

What’s New Here

  • The stupidity in sports is reaching insulting levels
  • Marina Mabrey ties WNBA record for most points in a game
  • David Peterson serves as ‘tough’ Mets casualty as trade deadline looms

Topics to Cover!

  • Business (5,084)
  • Entertainment (2,112)
  • General News (326)
  • Health (327)
  • Investigative Journalism (12)
  • Lifestyle (4)
  • Sports (12,259)
  • Technology (7,595)
  • World News (1,336)
  • Contact Us
  • Terms and Conditions
  • Privacy Policy
  • RSS
  • Contact News Room
  • Code of Conduct
  • Careers
  • Values
  • Advertise
  • DMCA

© 2025 - noti.group - All rights reserved - noti.group runs on 100% green energy.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • World News
  • Business
  • Health
  • Sports
  • Entertainment

© 2025 - noti.group - All rights reserved - noti.group runs on 100% green energy.