The content on this page was provided by an independent third party and syndicated by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Image Analysis Group Achieves SOC 2 Type II Certification, Setting the Enterprise Benchmark for Global Imaging CROs

Image Analysis Group Achieves SOC 2 Type II Certification, Setting the Enterprise Benchmark for Global Imaging CROs

DYNAMIKA™ delivers SOC 2 Type II–certified, AI‑driven imaging workflows, giving pharma and biotech secure, compliant oversight of imaging data in global trials. LONDON, UNITED KINGDOM,…

March 17, 2026

LISA RINNA OPENS UP ABOUT BULLYING, FAITH, PROTECTING HER DAUGHTERS FROM SOCIAL MEDIA

LISA RINNA OPENS UP ABOUT BULLYING, FAITH, PROTECTING HER DAUGHTERS FROM SOCIAL MEDIA

Lisa Rinna, (Real Housewives of Beverly Hills) appeared on the YouTube show Books That Changed My Life to talk childhood, career & Power of Positive…

March 17, 2026

LeVar Pompey Featured on Next Level CEO

LeVar Pompey Featured on Next Level CEO

FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Rev. LeVar Pompey, founder of DOMINION LIVING PROPERTIES LLC, is set to appear on Next Level CEO,…

March 17, 2026

Ricardo Regalado Featured on Next Level CEO

Ricardo Regalado Featured on Next Level CEO

FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Ricardo Regalado, founder of Route/Rozalado/Cleaning & Cocktails, is set to appear on Next Level CEO, where he…

March 17, 2026

The Colliding AI-Energy-Carbon Management Trilemma in the Age of Physical and Digital Infrastructure

The Colliding AI-Energy-Carbon Management Trilemma in the Age of Physical and Digital Infrastructure

At the 2026 American Data Centers Forum, SFLCT brings a frontline low-carbon energy systems perspective as compute places AI-Energy-Carbon Management at the forefront of the…

March 17, 2026

Sea Pointe Design & Remodel Celebrates 40 Years of Design-Build Excellence in Orange County

Sea Pointe Design & Remodel Celebrates 40 Years of Design-Build Excellence in Orange County

A Small Business Success Story in Irvine, Ca Reaching 40 years is a testament to the trust our clients place in us and the passion…

March 17, 2026

Arc Manor Launches Biggest Sale in Its History — Free Books, Pre-Releases & Iconic Preorders

Arc Manor Launches Biggest Sale in Its History — Free Books, Pre-Releases & Iconic Preorders

Award-winning indie press offers free Harry Turtledove titles, early access copies, and preorders for Mercedes Lackey’s Halfblood Chronicles finale Pre-release access is something most publishers…

March 17, 2026

Electroninks to Showcase Metal Complex Ink Innovations for Additive Electronics at IPC APEX EXPO 2026

Electroninks to Showcase Metal Complex Ink Innovations for Additive Electronics at IPC APEX EXPO 2026

Company to exhibit with Insulectro and deliver technical Power Chats on inkjet metalization and EMI shielding solutions AUSTIN, TX, UNITED STATES, March 17, 2026 /EINPresswire.com/…

March 17, 2026

NYBACS Surpasses 900 Global Company Incorporations Across 36+ Jurisdictions in Under Six Years Since Inception

NYBACS Surpasses 900 Global Company Incorporations Across 36+ Jurisdictions in Under Six Years Since Inception

New York–based global corporate services firm marks a major milestone supporting entrepreneurs and businesses across 36+ countries Reaching 900 global incorporations in under six years…

March 17, 2026

Actall and Buddi Announce Technical Cooperation for Integrated In-Facility and Community-Based Custody Tracking

Actall and Buddi Announce Technical Cooperation for Integrated In-Facility and Community-Based Custody Tracking

Integrating with HubSens will allow our shared customers to benefit” — Charles Lewinton, CTO and VP of the Americas, Buddi DENVER, CO, UNITED STATES, March…

March 17, 2026

Dr. Jessica Zummo Joins Women in Power TV

Dr. Jessica Zummo Joins Women in Power TV

FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Jessica Zummo, founder of Mountainside Holistic Clinic and Wellness Center, is set to appear on Women in…

March 17, 2026

Jonathan Ivey Featured on Next Level CEO

Jonathan Ivey Featured on Next Level CEO

FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Jonathan Ivey, founder of The Pensacola Music Academy LLC, is set to appear on Next Level CEO,…

March 17, 2026

Laura Hart to Appear on Women In Power TV

Laura Hart to Appear on Women In Power TV

FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Laura Hart, Executive Director of the Salida Circus Outreach Foundation, is set to appear on Women in…

March 17, 2026

Advanced EzGEL Tear Trough Treatment for Under Eye Rejuvenation at Forever Young Aesthetics in Birmingham, MI

Advanced EzGEL Tear Trough Treatment for Under Eye Rejuvenation at Forever Young Aesthetics in Birmingham, MI

Non surgical under eye filler treatment focuses on natural correction, precise technique, and conservative aesthetic results. Under eye treatment is not about adding volume.” —…

March 17, 2026

Amid Deepening Polarization, Book Reveals Blueprint to Rebuild Trust—in Communities, Not Washington, Brussels or Davos

Amid Deepening Polarization, Book Reveals Blueprint to Rebuild Trust—in Communities, Not Washington, Brussels or Davos

Richard Flyer’s “Birthing the Symbiotic Age” Draws on Global Grassroots Successes to Offer Replicable “Symbiotic Culture” for Local Cooperation and Resilience. The world stands on…

March 17, 2026

Elizabeth Gibbar Joins Women in Power TV

Elizabeth Gibbar Joins Women in Power TV

FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Elizabeth Gibbar, a mother, entrepreneur, community builder, and activist focused on maternal wellness, peer support, and systemic…

March 17, 2026

CardSight AI Completes Coverage of All Four Major Sports with Hockey Card Identification Launch

CardSight AI Completes Coverage of All Four Major Sports with Hockey Card Identification Launch

Platform delivers on Q1 promise; enhanced MCP server brings full trading card data access to AI assistants and builders When we launched Football identification earlier…

March 17, 2026

Honeybee Roofing Expands Metal Roofing Services in Rockford, IL to Meet Growing Homeowner Demand

Honeybee Roofing Expands Metal Roofing Services in Rockford, IL to Meet Growing Homeowner Demand

Local roofing company introduces durable, energy-efficient metal roofing systems as homeowners seek long-term protection and value. Homeowners today want more than just a roof—they want…

March 17, 2026

Jennie Rios Joins Women in Power TV

Jennie Rios Joins Women in Power TV

FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Jennie Rios, Digital Infrastructure Strategist and Private Fiber & Bulk Contract Expert, is set to appear on…

March 17, 2026

Federmeccanica:  Recovery of Taranto Steelworks (ex-Ilva) as a Global Model for Industrial Sovereignty and Green Steel

Federmeccanica: Recovery of Taranto Steelworks (ex-Ilva) as a Global Model for Industrial Sovereignty and Green Steel

Simone Bettini, President of Federmeccanica, advocates for a “Proactive Nationalization” strategy to secure Europe’s mechanical supply chain “The recovery of the former Ilva can become…

March 17, 2026

Dana Safety Supply Expands Border-to-Border Texas Coverage with New El Paso Facility

Dana Safety Supply Expands Border-to-Border Texas Coverage with New El Paso Facility

Major Public Safety equipment supplier chooses El Paso for its newest upfitting hub, marking the 11th location in the lone star state. Building a true…

March 17, 2026

Creative 3D Technologies Highlights ‘Factory-in-a-Box’ Manufacturing Platform as SXSW Focuses on the Future of AI

Creative 3D Technologies Highlights ‘Factory-in-a-Box’ Manufacturing Platform as SXSW Focuses on the Future of AI

What we’re building is the physical layer for the next generation of innovation, the technology stack to fabricate complex industrial products anywhere, as they are…

March 17, 2026

THE PROFESSIONAL GRAPPLING FEDERATION ENTERS WEEK 3 ADDING CREATOR TV TO ITS DISTRIBUTION NETWORK

THE PROFESSIONAL GRAPPLING FEDERATION ENTERS WEEK 3 ADDING CREATOR TV TO ITS DISTRIBUTION NETWORK

Kings Hold the Lead, Twisters Close the Gap And Phenoms, Wolverines Regroup In Week 3 With Exciting Races In The Team And Individual Points Standings…

March 17, 2026

ALOHA Launches National “Taste That Grows” Campaign Celebrating the Organic Ingredients Powering Its Breakout Growth

ALOHA Launches National “Taste That Grows” Campaign Celebrating the Organic Ingredients Powering Its Breakout Growth

LITTLETON, CO / ACCESS Newswire / March 17, 2026 / ALOHA, the fast-growing B Corp and Climate Label Certified plant-based protein brand, has launched its…

March 17, 2026

Muse Treatment Alcohol & Drug Rehab Los Angeles Publishes Critical New Resource on Website Examining Withdrawal Treatment for Xylazine-Linked “Zombie Drug” Exposure

Muse Treatment Alcohol & Drug Rehab Los Angeles Publishes Critical New Resource on Website Examining Withdrawal Treatment for Xylazine-Linked “Zombie Drug” Exposure

LOS ANGELES, CA – March 17, 2026 – PRESSADVANTAGE – Muse Treatment Alcohol & Drug Rehab Los Angeles has released a comprehensive new educational resource…

March 17, 2026

DJ Nu-Mark of Jurassic 5 to Join Trombone Shorty at Bridges Auditorium

DJ Nu-Mark of Jurassic 5 to Join Trombone Shorty at Bridges Auditorium

Innovative hip-hop DJ takes the stage March 21 CLAREMONT, CA, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Acclaimed producer, turntablist and Jurassic 5 member DJ…

March 17, 2026

TSHA Announces Second Annual Texas Revolution Rendezvous in San Antonio This April

TSHA Announces Second Annual Texas Revolution Rendezvous in San Antonio This April

SAN ANTONIO, TX, UNITED STATES, March 17, 2026 /EINPresswire.com/ — The Texas State Historical Association (TSHA) is proud to announce the return of the Texas…

March 17, 2026

South Denver Therapy Opens Second Castle Rock Office, Expands Teen and Individual Therapy Services

South Denver Therapy Opens Second Castle Rock Office, Expands Teen and Individual Therapy Services

Castle Rock mental health practice adds EMDR, teen therapy, and anxiety counseling at new Maleta Lane location. CASTLE ROCK, CO, UNITED STATES, March 17, 2026…

March 17, 2026

STOR MiniMAP™ Brings Professional-Grade Food Preservation to Kitchens

STOR MiniMAP™ Brings Professional-Grade Food Preservation to Kitchens

In professional kitchens, prep time is money. At home, it’s sanity.” — Chrissy Ford, CEO and Founder of STOR BROOMFIELD, CO, UNITED STATES, March 17,…

March 17, 2026

Asian-Led NutriWorks® Uplifts Traditional Chinese Medicine’s Power & Accessible Beauty with Reflexology Foot Patches

Asian-Led NutriWorks® Uplifts Traditional Chinese Medicine’s Power & Accessible Beauty with Reflexology Foot Patches

BOCA RATON, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — As costs of living increase, Americans nationwide are seeking affordable, accessible ways to feel both…

March 17, 2026

ACHS Announces New Marketplace Partnership with AzureWell

ACHS Announces New Marketplace Partnership with AzureWell

New ACHS–AzureWell partnership expands marketplace access, educational initiatives, and career opportunities in the wellness sector. AzureWell’s focus on whole-food-based nutrition and community-centered distribution aligns naturally…

March 17, 2026

Key Bridge Wireless Introduces Simplified Flat-Rate Pricing for CBRS

Key Bridge Wireless Introduces Simplified Flat-Rate Pricing for CBRS

tldr; $500 for your first 100 radios, $10 per radio thereafter. MCLEAN, VA, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Key Bridge Wireless Introduces Simplified…

March 17, 2026

Angel Davis Brings Powerful One-Act Play ‘A Beautiful Mess’ to Los Angeles Stage This May

Angel Davis Brings Powerful One-Act Play ‘A Beautiful Mess’ to Los Angeles Stage This May

A raw, thought-provoking theatrical experience exploring grief, healing, and the unseen conversations that shape us Grief is one of those universal shared experiences that we…

March 17, 2026

I-State Truck Center in Marshfield Moving to New Facility

I-State Truck Center in Marshfield Moving to New Facility

The I-State Truck Centers location in Marshfield has moved to a new location at 2503 East Heritage Dr., Marshfield, WI 54449 MARSHFIELD, WI, UNITED STATES,…

March 17, 2026

Computer Coach Launches AI Workforce Training Center to Prepare Professionals for the Future of Work

Computer Coach Launches AI Workforce Training Center to Prepare Professionals for the Future of Work

New AI training programs help professionals, businesses, and workforce organizations build practical artificial intelligence skills for real-world applications AI is no longer optional in the…

March 17, 2026

Developer James McManus Speaks Out on America Tonight Radio Alleging Fairbridge Seized Property After Term Sheet

Developer James McManus Speaks Out on America Tonight Radio Alleging Fairbridge Seized Property After Term Sheet

NEW YORK CITY, NY, UNITED STATES, March 17, 2026 /EINPresswire.com/ — New York developer James McManus discussed an $8.2 million financing dispute with Fairbridge Asset…

March 17, 2026

Moose Vinyl Acquires B-Side Records in Lemont, Illinois

Moose Vinyl Acquires B-Side Records in Lemont, Illinois

Popular record store to remain a community hub under new ownership CHICAGO, IL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Moose Vinyl, a technology company…

March 17, 2026

BCD and EyeOTmonitor Announce Strategic Partnership Ahead of ISC West 2026

BCD and EyeOTmonitor Announce Strategic Partnership Ahead of ISC West 2026

BCD and EyeOTmonitor announce a strategic partnership delivering real-time visibility across modern video surveillance infrastructure at ISC West 2026. Security teams need more than device…

March 17, 2026

Technology and AI Luminary Neal Fishman Publishes Manifesto Calling for Global Licensing and Certification of AI Systems

Technology and AI Luminary Neal Fishman Publishes Manifesto Calling for Global Licensing and Certification of AI Systems

Fishman’s manifesto draws parallels between AI governance and nuclear nonproliferation, urging nations to act before the window for meaningful oversight closes JERSEY CITY, NJ, UNITED…

March 17, 2026

Lenoss Medical Announces Successful Close of $6 Million Growth Bridge Financing

Lenoss Medical Announces Successful Close of $6 Million Growth Bridge Financing

Funding will accelerate commercial expansion, scale operations, and further strengthen clinical data generation Seeing doctors go from curious to convert is good, but seeing patients’…

March 17, 2026