This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Cabinets 4 Less Expands Fleet to Serve Scottsdale and Paradise Valley

Cabinets 4 Less Expands Fleet to Serve Scottsdale and Paradise Valley

Cabinets 4 Less announces a fleet expansion, bringing full-service, budget-friendly kitchen cabinet design and delivery

March 19, 2026

Kornerz Leadership Proudly Announces Their Newly Released Historic Retention Rate

Kornerz Leadership Proudly Announces Their Newly Released Historic Retention Rate

Proud Social Media App Proves That People Want To Feel Comfortable and Socialize Positively NEW YORK, NY, UNITED

March 19, 2026

Proxim Introduces GX60 Multi-Gigabit Outdoor Wireless Platform

Proxim Introduces GX60 Multi-Gigabit Outdoor Wireless Platform

New 60 GHz solution delivers up to 2 Gbps connectivity without the cost of fiber infrastructure Proxim Wireless

March 19, 2026

Soulful & Magnetic Global TV Special Hosted by Tiffany Cano to Stream March 27 Across Major Platforms

Soulful & Magnetic Global TV Special Hosted by Tiffany Cano to Stream March 27 Across Major Platforms

Transformational leaders share insights on intuition, empowerment, and conscious leadership during global livestream

March 19, 2026

OnlinePilatesClasses.com Launches New Flashcards for Classical Accessories

OnlinePilatesClasses.com Launches New Flashcards for Classical Accessories

This deck of 79 flashcards is a game-changer. This deck guides you through exercises and teaches you how to integrate

March 18, 2026

Whispers Within Us by Kathleen Huebner Inspires Readers to Trust Intuition and Co-Create with the Universe

Whispers Within Us by Kathleen Huebner Inspires Readers to Trust Intuition and Co-Create with the Universe

Kathleen Huebner, Napoleon Hill Certified Practitioner, best-selling author and speaker, shares a roadmap for

March 18, 2026

Qalitex Laboratories Expands Laboratory Testing for Beauty and Personal Care Products

Qalitex Laboratories Expands Laboratory Testing for Beauty and Personal Care Products

ISO 17025-accredited California lab offers stability, preservative, heavy metal, and Amazon beauty compliance testing

March 18, 2026

Cracking the Algorithm: ‘Prompt to Power’ Kit Helps YouTubers Script Viral Hooks and Descriptions Faster

Cracking the Algorithm: ‘Prompt to Power’ Kit Helps YouTubers Script Viral Hooks and Descriptions Faster

Scale your YouTube channel with "Prompt to Power." This AI toolkit helps creators script hooks, optimize descriptions,

March 18, 2026

Affiliate of Pacific Avenue Capital Partners Completes Acquisition of Care.com from IAC

Affiliate of Pacific Avenue Capital Partners Completes Acquisition of Care.com from IAC

LOS ANGELES, CA / ACCESS Newswire / March 18, 2026 / Pacific Avenue Capital Partners ("Pacific Avenue"), a Los

March 18, 2026

Go Industries Announces Enhanced OEM Manufacturing and Fabrication Services

Go Industries Announces Enhanced OEM Manufacturing and Fabrication Services

Richardson, TX – March 18, 2026 – PRESSADVANTAGE – Go Industries has announced enhanced custom manufacturing and

March 18, 2026

Nervous System Expert Christine Morgenstern Shin Featured at Oscars Week Gifting Lounge

Nervous System Expert Christine Morgenstern Shin Featured at Oscars Week Gifting Lounge

Showcasing nervous system healing and precision wellness through a $1,600 curated gift for Oscar nominees and industry

March 18, 2026

The World Is Out of Balance — A New Sleep Solution Launches on the March 20 Equinox to Help Restore It

The World Is Out of Balance — A New Sleep Solution Launches on the March 20 Equinox to Help Restore It

As global disruption rises, AchievingSleep.com introduces a simple, natural way to bring balance back to daily life.

March 18, 2026

Italian Aerospace Exports to US Soar by 8% Outpacing Market Growth Fivefold as Industry Leaders Converge at ADSS Seattle

Italian Aerospace Exports to US Soar by 8% Outpacing Market Growth Fivefold as Industry Leaders Converge at ADSS Seattle

SEATTLE, WA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Italian aerospace exports to the United States rose

March 18, 2026

OneWell Health Care Announces Partnership with AidRx to Transform Medication Management in the Philadelphia Market

OneWell Health Care Announces Partnership with AidRx to Transform Medication Management in the Philadelphia Market

OneWell Health Care Announces Strategic Partnership with AidRx to Enhance Medication Management and Patient Safety

March 18, 2026

Zydoc Showcases HIPAA-Compliant AI Documentation Solutions for Neuro-Ophthalmology at NANOS 2026 in Boston

Zydoc Showcases HIPAA-Compliant AI Documentation Solutions for Neuro-Ophthalmology at NANOS 2026 in Boston

As data security concerns rise, Zydoc highlights secure U.S.-based documentation solutions for neuro-ophthalmologists.

March 18, 2026

Austin Pool Deck Safety: VistaStone Overlay Reminder Issued for Summer

Austin Pool Deck Safety: VistaStone Overlay Reminder Issued for Summer

Bennett Outdoor Living reminds Austin homeowners about VistaStone's slip-resistant properties which meets local safety

March 18, 2026

DFW Kitchen Remodel: Spring Timing Guide Released for Homeowners

DFW Kitchen Remodel: Spring Timing Guide Released for Homeowners

Legacy Contracting & Construction, LLC releases spring timing guidance for Dallas-Fort Worth kitchen remodels.

March 18, 2026

Nahla Chirco to Appear on Women In Power TV

Nahla Chirco to Appear on Women In Power TV

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Nahla Chirco, founder of R&N Family Medical Practice, LLC,

March 18, 2026

The Merchant Risk Council Releases 2026 Global eCommerce Payments & Fraud Report

The Merchant Risk Council Releases 2026 Global eCommerce Payments & Fraud Report

New report reveals key trends in payments innovation, fraud prevention, and evolving risks shaping global eCommerce

March 18, 2026

Joshua Whitt Joins Operation CEO

Joshua Whitt Joins Operation CEO

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — JD Whitt, founder of MAVTAC Firearms & Training Academy, is

March 18, 2026

Kingdom & Co. Breaks Ground on Juniper Ridge Estate in Henderson’s Premier MacDonald Highlands Community

Kingdom & Co. Breaks Ground on Juniper Ridge Estate in Henderson’s Premier MacDonald Highlands Community

Luxury Design-Build Firm Launches Signature Spec Home Slated for Completion by End of 2026; Property to Be Offered for

March 18, 2026

Video Interview: Successful Pilot-Scale Run with Cayman Chemical Validates eXoZymes’ Technology and Scalability

Video Interview: Successful Pilot-Scale Run with Cayman Chemical Validates eXoZymes’ Technology and Scalability

eXoZymes Inc. (NASDAQ:EXOZ)This pilot run is an important validation of our cell-free platform, demonstrating that it

March 18, 2026

Richard Bland College Announces New Board of Visitors

Richard Bland College Announces New Board of Visitors

SOUTH PRINCE GEORGE, VA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Today Gov. Abigail Spanberger announced

March 18, 2026

Daniel McBride Joins Operation CEO

Daniel McBride Joins Operation CEO

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Daniel McBride, Co‑Owner and A&P/IA certificated expert at

March 18, 2026

Chayla Pica Joins Women in Power TV

Chayla Pica Joins Women in Power TV

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Chayla Pica, tattoo artist and founder of Soulful Tattoo

March 18, 2026

Justyne Albright to Appear on Women In Power TV

Justyne Albright to Appear on Women In Power TV

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Justyne Albright, equestrian trainer and instructor, is set to

March 18, 2026

Jennifer Bacani McKenney, MD, Joins Women in Power TV

Jennifer Bacani McKenney, MD, Joins Women in Power TV

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Jennifer Bacani McKenney, MD, founder of The Remote Scribe

March 18, 2026

NextDAY Cabinets Beltsville Showroom Expands Kitchen Cabinets Selection with Enhanced Design Services for Maryland Contractors

NextDAY Cabinets Beltsville Showroom Expands Kitchen Cabinets Selection with Enhanced Design Services for Maryland Contractors

BELTSVILLE, MD – March 18, 2026 – PRESSADVANTAGE – NextDAY Cabinets Beltsville Showroom has expanded its wholesale

March 18, 2026

The Club at Mediterra Maintains Elite Status, Announces New Sports & Lifestyle Center

The Club at Mediterra Maintains Elite Status, Announces New Sports & Lifestyle Center

Elite recognition and strategic investment reinforce Mediterra’s position among the nation’s top private clubs. Our

March 18, 2026

Public Health Action Network Is Accepting Proposals for Projects That Reduce Transmission of Airborne Pathogens

Public Health Action Network Is Accepting Proposals for Projects That Reduce Transmission of Airborne Pathogens

PHAN welcomes proposals from individuals, researchers, engineers, public health practitioners, and innovators committed

March 18, 2026

Voggia Introduces a New Editorial Standard for Gastronomy, Style, and the Modern Good Life

Voggia Introduces a New Editorial Standard for Gastronomy, Style, and the Modern Good Life

Istanbul-based Voggia publishes in English and Turkish, offering a research-driven perspective on fine dining, cocktail

March 18, 2026

Taylor Voiselle Featured on Next Level CEO

Taylor Voiselle Featured on Next Level CEO

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Taylor Voiselle, founder of PRIMARIX Inc., is set to appear on

March 18, 2026

ALM Automotive Expands Middle Georgia Presence With Acquisition of 5 Major Dealerships

ALM Automotive Expands Middle Georgia Presence With Acquisition of 5 Major Dealerships

ATLANTA, GA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — ALM Automotive, one of the Southeast’s fastest‑growing

March 18, 2026

Qalitex Laboratories Expands Mycotoxin Testing Capabilities

Qalitex Laboratories Expands Mycotoxin Testing Capabilities

ISO 17025 lab outlines aflatoxin, ochratoxin, and fumonisin testing for supplement brands against FDA, USP

March 18, 2026

Jarryd Loyd Featured on Next Level CEO

Jarryd Loyd Featured on Next Level CEO

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Jarryd Loyd, a leader in finance and private equity, is set to

March 18, 2026

Dr. Natasha Williams Delivers Transformative Black History Month Address at Vermont State University

Dr. Natasha Williams Delivers Transformative Black History Month Address at Vermont State University

International psychologist Dr. Natasha Williams shares insights on self-care, leadership, and sustainable success

March 18, 2026

Liv Hospital Launches Comprehensive Guide to Recognize Early Cancer Symptoms and Improve Early Detection

Liv Hospital Launches Comprehensive Guide to Recognize Early Cancer Symptoms and Improve Early Detection

NEW YORK, NY, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Liv Hospital today launched an informative guide to

March 18, 2026

Alex Baldwin Joins Operation CEO

Alex Baldwin Joins Operation CEO

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Alex Baldwin, founder of Minnesota Structures, is set to appear

March 18, 2026

Introducing the Agent Skills Security Index

Introducing the Agent Skills Security Index

The Agent Skills Security Index community powered by Tego is a public database that analyzes and maps security risks

March 18, 2026

Sage Bionetworks Partners with NYU Langone Health to Build Data Infrastructure for NIH’s Complement-ARIE Program

Sage Bionetworks Partners with NYU Langone Health to Build Data Infrastructure for NIH’s Complement-ARIE Program

New data hub will accelerate development and adoption of human-based New Approach Methodologies The NYU Langone-Sage

March 18, 2026