The content on this page was provided by an independent third party and syndicated by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

GREEN LIGHT FOR ONE OF ITALY’S LARGEST ENERGY STORAGE PROJECTS

GREEN LIGHT FOR ONE OF ITALY’S LARGEST ENERGY STORAGE PROJECTS

TERNA, Italy’s national transmission system operator approves the grid connection for Airengy’s (TASE: ARNG) massive 3 GWh storage capacity project Airengy (TASE:ARNG) Obtaining the grid…

March 18, 2026

VerbaFlo Raises $7M to Expand AI Leasing and Communications Platform for Student Housing and Multifamily Operators

VerbaFlo Raises $7M to Expand AI Leasing and Communications Platform for Student Housing and Multifamily Operators

SAN FRANCISCO , CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — VerbaFlo, an AI communications platform built for student housing and multifamily operators, today announced…

March 18, 2026

Vokon at ISLE 2026: Showcasing Next-Gen DSP Technology as a China Commercial Audio Amplifier Manufacturer

Vokon at ISLE 2026: Showcasing Next-Gen DSP Technology as a China Commercial Audio Amplifier Manufacturer

GUANGZHOU, GUANGDONG, CHINA, March 18, 2026 /EINPresswire.com/ — The rapid evolution of smart display technology and audio-visual convergence has reached a new milestone at the…

March 18, 2026

Voiso Earns 49 Badges in G2 Spring 2026 Report, Including 11 Leader Recognitions

Voiso Earns 49 Badges in G2 Spring 2026 Report, Including 11 Leader Recognitions

SINGAPORE, SG – March 18, 2026 – PRESSADVANTAGE – Voiso, a global provider of contact center software, has been recognized with 49 badges in the…

March 18, 2026

All Pro Home Improvement and Roofing Announces Roof Installation Expansion

All Pro Home Improvement and Roofing Announces Roof Installation Expansion

VINELAND, NJ – March 18, 2026 – PRESSADVANTAGE – All Pro HI and Roofing – Vineland, NJ has expanded its service line to include roof…

March 18, 2026

Aspire Allergy & Sinus Physician Highlights Promising Research on Needle-Free Treatment for Severe Allergic Reactions

Aspire Allergy & Sinus Physician Highlights Promising Research on Needle-Free Treatment for Severe Allergic Reactions

Could a nasal spray replace EpiPens? Aspire Allergy & Sinus Dr. Haley Overstreet highlights new research on needle-free treatment for severe allergic reactions. Epinephrine saves…

March 18, 2026

Henderson State Bank Expands HSA Program to Support ACA Enrollees and Combat Rising Healthcare Costs

Henderson State Bank Expands HSA Program to Support ACA Enrollees and Combat Rising Healthcare Costs

Henderson State Bank is reaffirming its commitment to community financial health by providing a HSA vehicle. “At Henderson State Bank, we understand that managing healthcare…

March 18, 2026

Top Frozen Cephalopods Manufacturers Gain Momentum as Global Seafood Demand Continues to Rise

Top Frozen Cephalopods Manufacturers Gain Momentum as Global Seafood Demand Continues to Rise

QINGDAO CITY, SHANDONG PROVINCE, CHINA, March 18, 2026 /EINPresswire.com/ — The global frozen seafood industry has experienced steady expansion in recent years, with frozen cephalopods…

March 18, 2026

Vimi Fasteners announces participation of Heading to Seattle for ADSS 2026

Vimi Fasteners announces participation of Heading to Seattle for ADSS 2026

Vimi, leader in high-precision fastening systems joins global industry giants in Seattle to showcase advanced engineering solutions for aviation and defense At ADSS 2026, Vimi…

March 18, 2026

Top Diesel Generator Manufacturers and the Global Trends Driving the Industry Forward

Top Diesel Generator Manufacturers and the Global Trends Driving the Industry Forward

FOSHAN CITY, GUANGDONG PROVINCE, CHINA, March 18, 2026 /EINPresswire.com/ — The global diesel generator market continues to expand as industries, infrastructure projects, and commercial operations…

March 18, 2026

The Philippines Joins the HealthAI Global Regulatory Network to Advance Responsible AI Adoption

The Philippines Joins the HealthAI Global Regulatory Network to Advance Responsible AI Adoption

By joining HealthAI’s GRN, the country advances its health journey and supports global adoption of responsible, cooperative AI in Health Through strategic investment in AI,…

March 18, 2026

Best Heavy Equipment Financing Companies 2026: Updated Rankings and Analysis Released

Best Heavy Equipment Financing Companies 2026: Updated Rankings and Analysis Released

IRAEmpire has released a new list of the best heavy equipment financing companies in USA to help consumers DALLAS, TX, UNITED STATES, March 18, 2026…

March 18, 2026

Katie Anne, LLC Launches Comprehensive Ministry to Support Divorced Christian Women in Rebuilding Biblical Identity

Katie Anne, LLC Launches Comprehensive Ministry to Support Divorced Christian Women in Rebuilding Biblical Identity

NASHVILLE, TN, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Katie Anne, LLC announces an expanding ministry dedicated to helping divorced Christian women rebuild their lives…

March 18, 2026

Is Post-Quantum Cryptography the Next Y2K Moment for Global Digital Infrastructure?

Is Post-Quantum Cryptography the Next Y2K Moment for Global Digital Infrastructure?

Are enterprises ready for a Y2K-scale disruption as post-quantum cryptography reshapes digital security? BENGALURU, KARNATAKA, INDIA, March 18, 2026 /EINPresswire.com/ — eMudhra today raised a…

March 18, 2026

California SBDC Hosts Statewide Advocacy Day at the Capitol in Celebration of National SBDC Day

California SBDC Hosts Statewide Advocacy Day at the Capitol in Celebration of National SBDC Day

California SBDC to hold more than 95 meetings with members of the California State Assembly and State Senate Our teams are on the ground in…

March 18, 2026

Cmax-Textile: Global Leading Sport Socks Manufacturer Customization and Quality

Cmax-Textile: Global Leading Sport Socks Manufacturer Customization and Quality

ZHEJIANG, ZHEJIANG, CHINA, March 18, 2026 /EINPresswire.com/ — The global footwear and apparel industry is undergoing a seismic shift. As we navigate through 2026, the…

March 18, 2026

Phoenix Father Launches AI Pet Health App After Losing Three Dogs to Cancer

Phoenix Father Launches AI Pet Health App After Losing Three Dogs to Cancer

VetGPT hits the App Store — AI pet health for 64+ species, built by a solo founder who lost three dogs to cancer while becoming…

March 18, 2026

Business Insurance Health Launches Free Valuation Tool Linking HR and Benefits Quality to Exit Price

Business Insurance Health Launches Free Valuation Tool Linking HR and Benefits Quality to Exit Price

New calculator benchmarks ten workforce risk categories against four national transaction databases to estimate how HR gaps affect small business sale prices Founders focus on…

March 18, 2026

DomainsByOwner.com Brings Subscription-Based Domain Sales to a Global Marketplace

DomainsByOwner.com Brings Subscription-Based Domain Sales to a Global Marketplace

DomainsByOwner.com introduces a subscription-based, commission-free marketplace enabling direct domain sales between buyers and owners worldwide. Our subscription model removes commissions and puts control back in…

March 18, 2026

A Buyer’s Guide to Choosing a Professional Smart Monitor Supplier in China: Quality Standards from PERFECT DISPLAY

A Buyer’s Guide to Choosing a Professional Smart Monitor Supplier in China: Quality Standards from PERFECT DISPLAY

SHENZHEN, GUANGDONG, CHINA, March 18, 2026 /EINPresswire.com/ — As the digital landscape evolves, the demand for sophisticated visual solutions has propelled the professional monitor market…

March 18, 2026

Behind the Security: PERFECT DISPLAY as a China Top 10 OEM CCTV Monitor Supplier with UL Certification

Behind the Security: PERFECT DISPLAY as a China Top 10 OEM CCTV Monitor Supplier with UL Certification

SHENZHEN, GUANGDONG, CHINA, March 18, 2026 /EINPresswire.com/ — The global security landscape is undergoing a profound transformation, driven by an unprecedented surge in demand for…

March 18, 2026

High-Performance ODM LED Display Solution from China: PERFECT DISPLAY Earns CB and ROHS Certification

High-Performance ODM LED Display Solution from China: PERFECT DISPLAY Earns CB and ROHS Certification

SHENZHEN, GUANGDONG, CHINA, March 18, 2026 /EINPresswire.com/ — In the rapidly evolving landscape of visual technology, the demand for reliable and sustainable display solutions has…

March 18, 2026

James Sanson Ranked Top Listing Agent in the City of Maricopa, AZ with 1,200 Closed Sales

James Sanson Ranked Top Listing Agent in the City of Maricopa, AZ with 1,200 Closed Sales

Maricopa home sellers gain a measurable edge with the city’s most credentialed listing specialist in zip codes 85138 and 85139. Most sellers in Maricopa do…

March 18, 2026

China Leading Curved Monitor Factory: How PERFECT DISPLAY is Shaping the Future of Immersive Displays

China Leading Curved Monitor Factory: How PERFECT DISPLAY is Shaping the Future of Immersive Displays

SHENZHEN, GUANGDONG, CHINA, March 18, 2026 /EINPresswire.com/ — The Inflection Point of Visual Revolution The global display industry is witnessing a profound paradigm shift. For…

March 18, 2026

Resolution to commence major 45-hole drilling at Golden Gate to define scale of Gold System Targeting Maiden Resource

Resolution to commence major 45-hole drilling at Golden Gate to define scale of Gold System Targeting Maiden Resource

RLMLF (NASDAQ:Resolution Minerals) IDAHO, ID, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Resolution Minerals Ltd. (NASDAQ: RLMLF) has announced a major Phase 2 drilling program…

March 18, 2026

Tinsel Magazine Profiles Sarah Soda, the Creator Behind TikTok’s 1.3 Million-Follower Prank Call Act

Tinsel Magazine Profiles Sarah Soda, the Creator Behind TikTok’s 1.3 Million-Follower Prank Call Act

An Exclusive reveals how a doctorate-holding clinician and self-taught voice actress built one of TikTok’s most demanding live acts — with no agent or manager…

March 18, 2026

Top 10 Professional Security Monitor Manufacturer: PERFECT DISPLAY’s Latest Tech at CANTON FAIR

Top 10 Professional Security Monitor Manufacturer: PERFECT DISPLAY’s Latest Tech at CANTON FAIR

SHENZHEN, GUANGDONG, CHINA, March 18, 2026 /EINPresswire.com/ — The global landscape of display technology is undergoing a transformative shift, driven by the demand for higher…

March 18, 2026

China Leading OLED Monitor Exporter: PERFECT DISPLAY Obtains KC and PSE Certification for Global Expansion

China Leading OLED Monitor Exporter: PERFECT DISPLAY Obtains KC and PSE Certification for Global Expansion

SHENZHEN, GUANGDONG, CHINA, March 18, 2026 /EINPresswire.com/ — Industry Leadership and the New Frontier of Visual Excellence In the rapidly evolving landscape of visual technology,…

March 18, 2026

ODM Desktop PC Monitor Factory from China: Comparing PERFECT DISPLAY Standards vs. Market Peers at COMPUTEX

ODM Desktop PC Monitor Factory from China: Comparing PERFECT DISPLAY Standards vs. Market Peers at COMPUTEX

SHENZHEN, GUANGDONG, CHINA, March 18, 2026 /EINPresswire.com/ — In the rapidly evolving landscape of visual technology, the role of an ODM Desktop PC Monitor Factory…

March 18, 2026

Scaling Business with the Best Gaming Monitor Brand from China: A Guide from PERFECT DISPLAY

Scaling Business with the Best Gaming Monitor Brand from China: A Guide from PERFECT DISPLAY

SHENZHEN, GUANGDONG, CHINA, March 18, 2026 /EINPresswire.com/ — The Strategic Shift in the Global Gaming Market The global esports market has witnessed an unprecedented surge…

March 18, 2026

High-priority drill targets identified at Star Range Silver-Antimony Project in Utah

High-priority drill targets identified at Star Range Silver-Antimony Project in Utah

Diablo Resources (OTCQB:DBORF) BEAVER COUNTY, UT, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Diablo Resources Ltd. (OTCQB: DBORF) has identified high-priority drill targets at its…

March 18, 2026

GoWish Selects Bonzer as Global SEO Partner: ‘We want to be the Pinterest of gift inspiration’

GoWish Selects Bonzer as Global SEO Partner: ‘We want to be the Pinterest of gift inspiration’

With over 17 million users and a massive international rollout underway, the leading wishlist platform GoWish has selected Bonzer as its global SEO partner. We…

March 18, 2026

Market Leaders and Innovations: Spotlight on Top Mushroom In Brine Manufacturers

Market Leaders and Innovations: Spotlight on Top Mushroom In Brine Manufacturers

LINYI CITY, SHANDONG PROVINCE, CHINA, March 18, 2026 /EINPresswire.com/ — The preserved mushroom sector has become one of the most active segments within the global…

March 18, 2026

Top Sidewall Conveyor Belt Manufacturers: A Comprehensive Look at the Industry’s Leading Players

Top Sidewall Conveyor Belt Manufacturers: A Comprehensive Look at the Industry’s Leading Players

QINGDAO CITY, SHANDONG PROVINCE, CHINA, March 18, 2026 /EINPresswire.com/ — Sidewall conveyor belts have become an essential component in bulk material handling systems worldwide. Unlike…

March 18, 2026

Print To Brand Delivers Custom Printing Solutions That Help Businesses Build Stronger Brand Visibility

Print To Brand Delivers Custom Printing Solutions That Help Businesses Build Stronger Brand Visibility

DALLAS, TX, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Businesses today face increasing pressure to maintain a consistent and professional brand image across every customer…

March 18, 2026

John Craig Establishes One of the Fastest-Growing Insurance Agencies in Freehold, New Jersey

John Craig Establishes One of the Fastest-Growing Insurance Agencies in Freehold, New Jersey

John Craig, owner of Craig Financial Group, LLC, has rapidly positioned his agency as one of the fastest-growing insurance providers in Freehold, New Jersey. With…

March 18, 2026

Innovation and Expansion: Insights into Top Powder Filling Machine Manufacturers

Innovation and Expansion: Insights into Top Powder Filling Machine Manufacturers

SHANGHAI CITY, CHINA, March 18, 2026 /EINPresswire.com/ — The global powder filling machine market continues to grow as demand from the food, pharmaceutical, and chemical…

March 18, 2026

Hydraulic Industry Spotlight: Top Directional Valve Manufacturers and Technological Advancements

Hydraulic Industry Spotlight: Top Directional Valve Manufacturers and Technological Advancements

SHIJIAZHUANG CITY, HEBEI PROVINCE, CHINA, March 18, 2026 /EINPresswire.com/ — Directional valves serve as the critical control elements in hydraulic circuits, determining the path, pressure,…

March 18, 2026

Truelist Launches Unlimited Email Validation at a Fixed Monthly Price

Truelist Launches Unlimited Email Validation at a Fixed Monthly Price

Email marketers and developers can now validate unlimited emails with no credits or overages — starting at $39/month, with a free plan available. Email validation…

March 18, 2026

Western NY Employment Attorney Launches Advice Series on Protecting Your Livelihood in the Age of AI

Western NY Employment Attorney Launches Advice Series on Protecting Your Livelihood in the Age of AI

Survival Guide Series Targets AI Impact and “Robot-Bosses” for Rochester and Buffalo Workers. This series isn’t just about the technology; it’s about the hard-nosed legal…

March 18, 2026