This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

SUVELL at IEEE PES T&D: Showcasing Excellence as a China Top Low Voltage Transformer Bushing Manufacturer

SUVELL at IEEE PES T&D: Showcasing Excellence as a China Top Low Voltage Transformer Bushing Manufacturer

WENZHOU, ZHEJIANG, CHINA, March 19, 2026 /EINPresswire.com/ — The global power distribution landscape is undergoing a

March 19, 2026

MSPs eye sustained revenue growth from hybrid IT, Westcon-Comstor finds

MSPs eye sustained revenue growth from hybrid IT, Westcon-Comstor finds

Global study shows cloud management and security lead commercial opportunities as partners move beyond deployment The

March 19, 2026

UK Breaking News24x7 Launches Updated Digital News Platform Covering UK Headlines

UK Breaking News24x7 Launches Updated Digital News Platform Covering UK Headlines

UK Breaking News24x7 announced an updated online news platform designed to publish UK-focused headlines and

March 19, 2026

Jasmine: China Top Glass Bottle Manufacturer Linking the Global Shift Toward Premium and Sustainable Packaging

Jasmine: China Top Glass Bottle Manufacturer Linking the Global Shift Toward Premium and Sustainable Packaging

SHANDONG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — Jasmine: China Top Glass Bottle Manufacturer Leading

March 19, 2026

China-Based Smooth Speed Air Jet Mill Supplier Announces New Micro-Powder Processing Innovations

China-Based Smooth Speed Air Jet Mill Supplier Announces New Micro-Powder Processing Innovations

WEIFANG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — The global industrial sector is currently witnessing a

March 19, 2026

2026 North American Inspiring Workplaces Awards Finalists in association with Engagedly announced

2026 North American Inspiring Workplaces Awards Finalists in association with Engagedly announced

World’s #1 PeopleFirst HR & Workplaces Awards – finalists include: COS, Equifax, Hitachi Energy, Macmillan

March 19, 2026

How China Top Low Voltage Transformer Bushing Manufacturer SUVELL is Transforming Power Grids at EP China

How China Top Low Voltage Transformer Bushing Manufacturer SUVELL is Transforming Power Grids at EP China

WENZHOU, ZHEJIANG, CHINA, March 19, 2026 /EINPresswire.com/ — The modernization of global electrical infrastructure

March 19, 2026

Best-in-Class Abatement System Exceeds GHG Benchmarks Outlined in Semiconductor Climate Consortium Whitepaper

Best-in-Class Abatement System Exceeds GHG Benchmarks Outlined in Semiconductor Climate Consortium Whitepaper

DAS Environmental Experts demonstrates >99.9 % CF₄ abatement efficiency for semiconductor manufacturing Moving

March 19, 2026

Poki Releases New Research on What Teens Are Doing on Their Phones at School

Poki Releases New Research on What Teens Are Doing on Their Phones at School

New research reveals American teens spend 70 minutes on their phones during the school day. Here is where that time is

March 19, 2026

China Best Automated Flat Air Grinder With Low Noise: How JINGXIN Enhances Grinding Accuracy

China Best Automated Flat Air Grinder With Low Noise: How JINGXIN Enhances Grinding Accuracy

WEIFANG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — As the global manufacturing sector transitions toward

March 19, 2026

Top Advantages Offered by a China Top Battery Materials Grinding Machine Factory

Top Advantages Offered by a China Top Battery Materials Grinding Machine Factory

WEIFANG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — As the global demand for electric vehicles (EVs) and

March 19, 2026

Red Sift joins Future Fifty 2026 cohort unveiled by Chancellor at Downing Street

Red Sift joins Future Fifty 2026 cohort unveiled by Chancellor at Downing Street

UK headquartered cybersecurity scaleup joins 25 high-growth UK tech companies recognized by Chancellor Rachel Reeves.

March 19, 2026

Global Sourcing Partner: Buying from JianHongXing, the Best Used Construction Machinery Supplier from China

Global Sourcing Partner: Buying from JianHongXing, the Best Used Construction Machinery Supplier from China

HEFEI, ANHUI, CHINA, March 19, 2026 /EINPresswire.com/ — In the rapidly evolving landscape of global infrastructure,

March 19, 2026

Jasmine: The Global Supplier Of Custom Glass Bottles and Jars Redefining Premium Packaging From China to the World

Jasmine: The Global Supplier Of Custom Glass Bottles and Jars Redefining Premium Packaging From China to the World

SHANDONG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — Jasmine: The Global Supplier Of Custom Glass Bottles

March 19, 2026

China CNC Milling Manufacturer DAZAO to Attend Metalloobrabotka 2026

China CNC Milling Manufacturer DAZAO to Attend Metalloobrabotka 2026

XIAMEN, FUJIAN, CHINA, March 19, 2026 /EINPresswire.com/ — DAZAO, a CNC milling manufacturer based in China, has

March 19, 2026

Why JINGXIN Ranks Among the Top 10 Ultrafine Mill Manufacturers in China

Why JINGXIN Ranks Among the Top 10 Ultrafine Mill Manufacturers in China

WEIFANG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — The industrial landscape for powder processing

March 19, 2026

Roberts & Ryan Expands its Internship Program Through its Partnership with DoW SkillBridge

Roberts & Ryan Expands its Internship Program Through its Partnership with DoW SkillBridge

NEW YORK, NY, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Roberts & Ryan has welcomed two military interns

March 19, 2026

INDIGO Biosciences Launches CHRM1 (Cholinergic Receptor, Muscarinic 1) Reporter Assays for Cognitive Drug Discovery

INDIGO Biosciences Launches CHRM1 (Cholinergic Receptor, Muscarinic 1) Reporter Assays for Cognitive Drug Discovery

New Assay Expands INDIGO’s GPCR Portfolio and Supports Development of Next-Generation CNS-Related Therapeutics STATE

March 19, 2026

Lehigh County to Premiere ‘Voices of Recovery’ Campaign, Expanding Family-Focused Support in Response to Opioid Crisis

Lehigh County to Premiere ‘Voices of Recovery’ Campaign, Expanding Family-Focused Support in Response to Opioid Crisis

Public event to feature real recovery stories and launch new Journeys and Child Watch programs removing barriers to

March 19, 2026

WOMEN & WEALTH SUMMIT IGNITES BOLD CONVERSATIONS ON CAPITAL, OWNERSHIP AND FINANCIAL POWER

WOMEN & WEALTH SUMMIT IGNITES BOLD CONVERSATIONS ON CAPITAL, OWNERSHIP AND FINANCIAL POWER

Founder Ange Matthews Leads Cross-Industry Dialogue On Investing, Capital Strategy And The Shift From Six-Figure Income

March 19, 2026

Multifamily Property Management Turns to Digital Solutions For A better

Multifamily Property Management Turns to Digital Solutions For A better

The market moved. Some Commercial operators & asset owners moved with it. This is what they knew that others

March 19, 2026

Wohnung verkaufen in Berlin: Diese Bezirke verkaufen sich 2026 am schnellsten in der Hauptstadt

Wohnung verkaufen in Berlin: Diese Bezirke verkaufen sich 2026 am schnellsten in der Hauptstadt

Neue Auswertung zeigt deutliche Unterschiede bei Verkaufsdauer und Nachfrage – Makler David Gramzow erklärt, wo

March 19, 2026

Top 5 Advantages of Partnering with a Leading Air Classifier Exporter With ISO9001 Certification

Top 5 Advantages of Partnering with a Leading Air Classifier Exporter With ISO9001 Certification

WEIFANG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — The global powder processing industry continues to

March 19, 2026

Performance Analysis of a High-Performance Laboratory Pneumatic Pulverizer Supplier for R&D Applications

Performance Analysis of a High-Performance Laboratory Pneumatic Pulverizer Supplier for R&D Applications

WEIFANG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — As industries increasingly demand precision in particle

March 19, 2026

Advanced High-Tech Air Flow Mill Solutions vs. Traditional Grinding: A JINGXIN Comparative Study

Advanced High-Tech Air Flow Mill Solutions vs. Traditional Grinding: A JINGXIN Comparative Study

WEIFANG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — The industrial powder processing sector is experiencing

March 19, 2026

Driving Global Micronization: JINGXIN’s Multi-Sector Participation as a Professional Manufacturer

Driving Global Micronization: JINGXIN’s Multi-Sector Participation as a Professional Manufacturer

WEIFANG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — In an era of accelerating industrial innovation, precise

March 19, 2026

didlogic’s CSO Expands On The Next Phase Of Growth At The Company

didlogic’s CSO Expands On The Next Phase Of Growth At The Company

NEW YORK, NY – March 19, 2026 – PRESSADVANTAGE – didlogic, a global provider of SIP trunking and DID services, today

March 19, 2026

JINGXIN: Defining Standards as a Global Leading Stable Superfine Pulverizer Manufacturer

JINGXIN: Defining Standards as a Global Leading Stable Superfine Pulverizer Manufacturer

WEIFANG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — In the competitive world of industrial manufacturing,

March 19, 2026

A Practical Guide to Sourcing Equipment from a Highly Cost-Effective Air Jet Mill Exporter with CE Certification

A Practical Guide to Sourcing Equipment from a Highly Cost-Effective Air Jet Mill Exporter with CE Certification

WEIFANG, SHANDONG, CHINA, March 19, 2026 /EINPresswire.com/ — Shandong Jingxin Powder Equipment Technology Co., Ltd.,

March 19, 2026

Top Roof Top Awning Manufacturers: A Close Look at the Companies Leading the Global Market

Top Roof Top Awning Manufacturers: A Close Look at the Companies Leading the Global Market

TIANJIN CITY, CHINA, March 19, 2026 /EINPresswire.com/ — The global market for rooftop awning systems has experienced

March 19, 2026

Helical Fusion Completes Critical Components for ‘Helix HARUKA’ with RYOKI TOOL, Advancing Japan-Built Fusion Hardware

Helical Fusion Completes Critical Components for ‘Helix HARUKA’ with RYOKI TOOL, Advancing Japan-Built Fusion Hardware

Coil case parts and a prototype breeding blanket component mark a tangible manufacturing milestone for the Helix

March 19, 2026

Driving Sustainability: Commercial Solar Power Installation in Garfield

Driving Sustainability: Commercial Solar Power Installation in Garfield

Commercial solar power installation is now an important part of using cleaner energy. Solar panels, or photovoltaic

March 19, 2026

Shaping the Future of Functional Ingredients: Top Native Cyclodextrin Manufacturers

Shaping the Future of Functional Ingredients: Top Native Cyclodextrin Manufacturers

BINZHOU CITY, SHANDONG PROVINCE, CHINA, March 19, 2026 /EINPresswire.com/ — The global market for functional

March 19, 2026

NEQSOL Holding and Education Development Fund Continue PARLA Female Scholarship Program with Third Cohort

NEQSOL Holding and Education Development Fund Continue PARLA Female Scholarship Program with Third Cohort

Programs like PARLA are an investment in the future talent pipeline and leadership capacity of the country”— Kirill

March 19, 2026

GUATEMALA AS THE EPICENTER OF LATIN AMERICAN FASHION WITH SEMANA DE LA MODA

GUATEMALA AS THE EPICENTER OF LATIN AMERICAN FASHION WITH SEMANA DE LA MODA

From March 11 to 14, Semana de la Moda Guatemala 2026 positioned the country on Latin American fashion, where culture,

March 19, 2026

Indigenous Communities Gain New Access to Global Carbon Markets Through KMGBF-Aligned Initiative

Indigenous Communities Gain New Access to Global Carbon Markets Through KMGBF-Aligned Initiative

Indigenous communities gain access to global carbon markets through a new initiative removing upfront costs and

March 19, 2026

APOGEE GLOBAL RMS LAUNCHES EXECUTIVE GUIDE ON THE RISE OF AI IN LEADERSHIP AND ITS IMPACT ON EXECUTIVE TEAMS

APOGEE GLOBAL RMS LAUNCHES EXECUTIVE GUIDE ON THE RISE OF AI IN LEADERSHIP AND ITS IMPACT ON EXECUTIVE TEAMS

New strategic resource examines how artificial intelligence is reshaping executive decision-making, governance, and

March 19, 2026

Expert Guide to Model Agility: Reducing Vendor Lock-in with AI.cc’s One API Architecture

Expert Guide to Model Agility: Reducing Vendor Lock-in with AI.cc’s One API Architecture

SINGAPORE, SINGAPORE, SINGAPORE, March 19, 2026 /EINPresswire.com/ — In the rapidly evolving landscape of 2025 and

March 19, 2026

Top 3-Phase Asynchronous AC Motors Manufacturers Driving Growth in Electric Motor Industry

Top 3-Phase Asynchronous AC Motors Manufacturers Driving Growth in Electric Motor Industry

GUANGZHOU CITY, GUANGDONG PROVINCE, CHINA, March 19, 2026 /EINPresswire.com/ — The global electric motor industry

March 19, 2026

Top Cleanroom Wipes Manufacturers Shaping the Future of Contamination Control

Top Cleanroom Wipes Manufacturers Shaping the Future of Contamination Control

ZHONGSHAN CITY, GUANGDONG PROVINCE, CHINA, March 19, 2026 /EINPresswire.com/ — In industries where a single particle

March 19, 2026