This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Old South End Partnership Announces Coordinated Housing Pilot Backed by $1 Million in Initial Investment

Old South End Partnership Announces Coordinated Housing Pilot Backed by $1 Million in Initial Investment

TOLEDO, OH, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Today, the newly formed Old South End Partnership (OSE

March 19, 2026

HPS Flooring Seeks Expansion of Industrial Epoxy Flooring Services for New Jersey’s Warehouse and Food Service Sectors

HPS Flooring Seeks Expansion of Industrial Epoxy Flooring Services for New Jersey’s Warehouse and Food Service Sectors

Expansion of Industrial Epoxy Flooring Services Our mission has always been to provide reliability where it matters

March 19, 2026

Breaking the Mold at ACC.26: HeartLung.AI Emerges as the Only Exhibitor With Seven Scientific Presentations

Breaking the Mold at ACC.26: HeartLung.AI Emerges as the Only Exhibitor With Seven Scientific Presentations

NEW ORLEANS , LA, UNITED STATES, March 19, 2026 /EINPresswire.com/ — HeartLung.AI today announced that it will

March 19, 2026

Bell Rose Capital Inc. (OTCID: BELR) Eliminates $15 Million in Legacy Debt

Bell Rose Capital Inc. (OTCID: BELR) Eliminates $15 Million in Legacy Debt

COFIRMS NO REVERSE SPLIT IN THE FORESEEABLE FUTURE BOCA RATON, FL, UNITED STATES, March 19, 2026 /EINPresswire.com/ —

March 19, 2026

Ballers Seaport Announces Official Spring Opening

Ballers Seaport Announces Official Spring Opening

Boston’s First Outdoor Padel Courts Mark New Hub for Racquet Sports, Food, and Community Boston is an incredibly

March 19, 2026

Six-Figure Chicks Celebrates Launch of ‘Scottsdale Volume 2’ Featuring 18 Women Entrepreneurs

Six-Figure Chicks Celebrates Launch of ‘Scottsdale Volume 2’ Featuring 18 Women Entrepreneurs

E-book released March 7; audiobook coming in April and paperback edition in May SCOTTSDALE, AZ, UNITED STATES, March

March 19, 2026

Patriot Software’s Simple Rule for Scaling: “Engineer It”

Patriot Software’s Simple Rule for Scaling: “Engineer It”

Patriot is hiring engineers, product managers, and designers to support rapid growth. CANTON, OH / ACCESS Newswire /

March 19, 2026

Global survey reveals clean restrooms are now essential to winning repeat customers

Global survey reveals clean restrooms are now essential to winning repeat customers

MetrixLab research shows 100% agree dirty restrooms reflect poorly on the establishment, with the #1 contributing

March 19, 2026

Pharma Executives Converge on a Cautious Playbook for Agentic AI

Pharma Executives Converge on a Cautious Playbook for Agentic AI

Start narrow, build in guardrails, and plan to monitor for years – that was the consensus at a USEReady-hosted

March 19, 2026

STMicroelectronics’ GaN reference design targets motor-control applications in domestic appliances and industrial drives

STMicroelectronics’ GaN reference design targets motor-control applications in domestic appliances and industrial drives

Turnkey board and documentation cuts BOM and accelerates time to market STMicroelectronics (NYSE:STM)GENEVA,

March 19, 2026

Massive Bio Launches NexusPulse™, the Real-Time AI Signal Engine for Oncology Markets

Massive Bio Launches NexusPulse™, the Real-Time AI Signal Engine for Oncology Markets

Turning real-world clinical and biomarker data into always-on analytics and actionable signals for oncology teams.

March 19, 2026

AI Search Is Creating ‘Invisible Visits’ as Businesses Lose Website Traffic

AI Search Is Creating ‘Invisible Visits’ as Businesses Lose Website Traffic

New data suggests AI‑generated answers are reducing the need to click through to websites, shifting where customer

March 19, 2026

Meister Media Publications Named Finalist in Four Categories for 2026 Azbee Awards for Editorial Excellence

Meister Media Publications Named Finalist in Four Categories for 2026 Azbee Awards for Editorial Excellence

Categories featured include special issue coverage, state of the industry coverage, special print issue, and company

March 19, 2026

RxActuator Acquisition Disrupts Veterinary Care with Multispecies ‘Hospital-at-Home’ Infusion Platform

RxActuator Acquisition Disrupts Veterinary Care with Multispecies ‘Hospital-at-Home’ Infusion Platform

Journey Legacy Partners acquires RxActuator to scale first non-powered, 48-hour wearable infusion system for

March 19, 2026

Yamamoto Announces Midwest Laundries Inc. as Primary Distributor for Greater Chicagoland and Southern Wisconsin

Yamamoto Announces Midwest Laundries Inc. as Primary Distributor for Greater Chicagoland and Southern Wisconsin

Partnership Expands Market Access and Strengthens Local Customer Support Across the Region Yamamoto’s product portfolio

March 19, 2026

HIji RR Wins Two California Music Video Awards

HIji RR Wins Two California Music Video Awards

Electronic rock artist HIji RR wins two CALIFORNIA MUSIC VIDEO AWARDS for “Lucky Stars (feat. Monkey Warhol)”. Being

March 19, 2026

2026 Colorado Titan 100 Honorees

2026 Colorado Titan 100 Honorees

Titan CEO and headline sponsor Wipfli are pleased to announce the 2026 Colorado Titan 100 Being a Titan is not just a

March 19, 2026

AMPP Announces 2026 Advocacy Days Bringing Industry to Washington to Advance Infrastructure, Defense & Energy Policy

AMPP Announces 2026 Advocacy Days Bringing Industry to Washington to Advance Infrastructure, Defense & Energy Policy

AMPP Advocacy Days 2026 will bring experts to Washington to share technical insight with policymakers on protecting

March 19, 2026

Ink Different Tattoos Expands to Des Moines with New Apprenticeship at Lucky Gal Tattoo & Piercing

Ink Different Tattoos Expands to Des Moines with New Apprenticeship at Lucky Gal Tattoo & Piercing

In Partnership with Entrepreneur and Tattoo Artist Chris Pruisner, Ink Different Expands Its College-Alternative

March 19, 2026

Kevin Mackey and Christie Kramer-Codner of Epoch Concepts Named to 2026 Colorado Titan 100

Kevin Mackey and Christie Kramer-Codner of Epoch Concepts Named to 2026 Colorado Titan 100

LITTLETON, CO, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Epoch Concepts, LLC, a leading provider of IT

March 19, 2026

Private Communities Registry Announces 2026 Most Popular Lifestyle Communities in the U.S.

Private Communities Registry Announces 2026 Most Popular Lifestyle Communities in the U.S.

Annual Recognition Highlights Master-Planned, Gated, Golf, Lake, and 55+ Communities Generating the Highest Homebuyer

March 19, 2026

$8.25 Million Settlement Recovered in Catastrophic Commercial Truck Collision Case

$8.25 Million Settlement Recovered in Catastrophic Commercial Truck Collision Case

GLENDALE, CA, UNITED STATES, March 19, 2026 /EINPresswire.com/ — A catastrophic commercial truck collision has

March 19, 2026

Vislink Launches Dual-Modem DragonFly V 5G, Bringing Greater Resilience to Compact Camera Systems

Vislink Launches Dual-Modem DragonFly V 5G, Bringing Greater Resilience to Compact Camera Systems

The new DragonFly model enables two simultaneous cellular connections in a compact transmitter for reliable live video

March 19, 2026

Rapawzel Dog Grooming & Daycare Opens New Location on Manhattan’s Upper West Side

Rapawzel Dog Grooming & Daycare Opens New Location on Manhattan’s Upper West Side

Upper West Side pet owners are invited to visit Rapawzel at 211 W 80th St and experience the difference firsthand. NEW

March 19, 2026

A Decade of Gains Gold Prices Climb 300% Safe Haven Status in Focus

A Decade of Gains Gold Prices Climb 300% Safe Haven Status in Focus

Dubbed the “King of Safe Havens,” gold has experienced price fluctuations over the past decade but has maintained a

March 19, 2026

2.5 Tons of Honey Donated to St. Louis Hunger Relief Nonprofit

2.5 Tons of Honey Donated to St. Louis Hunger Relief Nonprofit

6,480 Bottle of Honey Will Help Fuel Fresh Meals For Those Facing Food Insecurity Across St. Louis Area and Beyond In the past two years,…

March 19, 2026

New Memoir ‘The Burn List’ Recounts One Woman’s Story of Abuse and Fallout in Higher Education

New Memoir ‘The Burn List’ Recounts One Woman’s Story of Abuse and Fallout in Higher Education

In her debut memoir, Julie Cruse recounts an abusive childhood and the personal and professional consequences she says followed her into higher education. This isn’t…

March 19, 2026

Private Money Funding Launches New Investor Platform and Sponsors Exclusive Golf Events Across California

Private Money Funding Launches New Investor Platform and Sponsors Exclusive Golf Events Across California

Scottsdale private credit firm launches a new platform for accredited investors and partners with Golf Execs for

March 19, 2026

Lea County, NM Partners with Catalis to Modernize Property Assessment System

Lea County, NM Partners with Catalis to Modernize Property Assessment System

Catalis Continues Expansion Across New Mexico Lea County is making an important investment in the future of its

March 19, 2026

Eyecon | RxSafe and LTC@Home Pharmacy Network Strengthen Partnership with Launch of LTC@Vantage Bundle

Eyecon | RxSafe and LTC@Home Pharmacy Network Strengthen Partnership with Launch of LTC@Vantage Bundle

New offering is designed to help independent pharmacies launch and scale long-term care at home services more

March 19, 2026

tagSpace Integrates with Story to Unlock the Future of IP Rights for Spatial AI

tagSpace Integrates with Story to Unlock the Future of IP Rights for Spatial AI

tagSpace and Story to solve IP rights for Spatial AI, creating a secure, programmable, decentralized system for

March 19, 2026

Bella Dental Group in El Cajon Acquires 3D Imaging System, Positioning Practice as Tech Leader Among San Diego Dentists

Bella Dental Group in El Cajon Acquires 3D Imaging System, Positioning Practice as Tech Leader Among San Diego Dentists

With cutting-edge 3D imaging, Bella Dental Group offers more accurate diagnoses, better outcomes, and a superior

March 19, 2026

Ohio Edison Announces Rate Increases Ahead of Summer 2026

Ohio Edison Announces Rate Increases Ahead of Summer 2026

Ohio Edison bills could jump $37 by summer thanks to Winter Storm Fern and a PJM capacity charge. Lock in a fixed rate

March 19, 2026

Carolina Signs and Wonders Hosts US Small Business Administration to Advance made in America and & Small Business Growth

Carolina Signs and Wonders Hosts US Small Business Administration to Advance made in America and & Small Business Growth

Carolina Signs and Wonders hosts SBA in Charlotte to support U.S. manufacturing and small business growth, representing

March 19, 2026

Vibes Tribe Launches First Digital Platform Focused on Nervous System Regulation for Midlife Women

Vibes Tribe Launches First Digital Platform Focused on Nervous System Regulation for Midlife Women

Vibes Tribe, a digital platform designed to help midlife women regulate their nervous systems and manage chronic

March 19, 2026

Philly Wellness Center Expands Proactive Health Capabilities with Genesis Regenerative’s RPA

Philly Wellness Center Expands Proactive Health Capabilities with Genesis Regenerative’s RPA

Dr. Catie Harris adds advanced non-cellular protein arrays to a comprehensive clinical toolkit that includes targeted

March 19, 2026

Zignature Introduces Seven Freeze-Dried Entrées, Expanding Limited-Ingredient Leadership into a Fast-Growing Category

Zignature Introduces Seven Freeze-Dried Entrées, Expanding Limited-Ingredient Leadership into a Fast-Growing Category

Complete & balanced, real meat-first recipes bring novel proteins and simplified nutrition to freeze-dried dog food

March 19, 2026

Freedom Ignited Announces “Honor in the Skies”: A Heart-Led Community Tribute to Dothan’s Military Families

Freedom Ignited Announces “Honor in the Skies”: A Heart-Led Community Tribute to Dothan’s Military Families

DOTHAN, AL, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Freedom Ignited, a 501(c)(3) non-profit organization,

March 19, 2026

Carebox to Host Interactive Session on Eliminating Recruitment Dead Ends at Patients as Partners 2026

Carebox to Host Interactive Session on Eliminating Recruitment Dead Ends at Patients as Partners 2026

Patients are not disengaging because they lack interest in research. They disengage when systems fail to connect.”—

March 19, 2026

Market Logic Network Begins Development of Subscription-Based Zoho Marketplace Extension for B2B Company Intelligence

Market Logic Network Begins Development of Subscription-Based Zoho Marketplace Extension for B2B Company Intelligence

New SaaS extension will bring OpenAPI-powered company data enrichment and AI-driven lead qualification to Zoho CRM

March 19, 2026