This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Cindy Schuler, PHR, SHRM-CP, CPC, ELI-MP, CPRW, Recognized By Influential Women, Leads HR Strategy At IntegriStar

Cindy Schuler, PHR, SHRM-CP, CPC, ELI-MP, CPRW, Recognized By Influential Women, Leads HR Strategy At IntegriStar

GAMBRILLS, MD, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Senior HR Leader, Certified Professional Coach, and

March 17, 2026

XOP Networks Integrates its Emergency Crash-Phone Platform with Cloud-Hosted IP-PBX

XOP Networks Integrates its Emergency Crash-Phone Platform with Cloud-Hosted IP-PBX

The integration enables enterprises to leverage XOP Networks’ proven Ringdown Firebar Conference Server (RFCS) with

March 17, 2026

Global Innovative Platforms (GIPL) Announces OTCID™ Quotation

Global Innovative Platforms (GIPL) Announces OTCID™ Quotation

Global Innovative Platforms confirms OTCID™ quotation as it advances commercialization of its VetBreath™ animal health

March 17, 2026

Austin Roofing: Canada’s Largest Roofing Contractor Leads the Industry in Steel Roof Coatings, Metal Roofing Systems

Austin Roofing: Canada’s Largest Roofing Contractor Leads the Industry in Steel Roof Coatings, Metal Roofing Systems

Metal roof coatings can out-perform a conventional membrane overlay which consists of installing thousands of screws

March 17, 2026

BroadAcre Apartments Opens Modern Residential Community in McCordsville, Indiana

BroadAcre Apartments Opens Modern Residential Community in McCordsville, Indiana

MCCORDSVILLE, IN, UNITED STATES, March 17, 2026 /EINPresswire.com/ — BroadAcre Apartments today announced the opening

March 17, 2026

Jeekeshen Chinnappen Releases New Book on the Entrepreneurial Mindset

Jeekeshen Chinnappen Releases New Book on the Entrepreneurial Mindset

Entrepreneur explores the neuroscience behind how founders think. NEW YORK, NY, UNITED STATES, March 17, 2026

March 17, 2026

The Maples Fort Worth Announces In-Network Agreements with UnitedHealthcare and Blue Cross Blue Shield, Expanding Access

The Maples Fort Worth Announces In-Network Agreements with UnitedHealthcare and Blue Cross Blue Shield, Expanding Access

The Maples Fort Worth Announces In-Network Agreements with UnitedHealthcare & Blue Cross Blue Shield, Expanding

March 17, 2026

Regenerative Orthopedics and Sports Medicine (ROSM) to Lead and Honor at AAOM OTX26

Regenerative Orthopedics and Sports Medicine (ROSM) to Lead and Honor at AAOM OTX26

ROSM co-founders Dr. John Ferrell and Dr. Sean Mulvaney to lead instruction at OTX26, where Dr. Mulvaney will receive

March 17, 2026

Done Right Hood and Fire Safety Calls Attention to Rising Restaurant Fire-Safety Concerns in New York and South Florida

Done Right Hood and Fire Safety Calls Attention to Rising Restaurant Fire-Safety Concerns in New York and South Florida

Done Right HFS says policy lag, uneven enforcement, aging code frameworks make Commercial Hood cleaning and Fire

March 17, 2026

Mobisoft Infotech Is Digitizing Global Transport Operations with Intelligent Fleet Technology

Mobisoft Infotech Is Digitizing Global Transport Operations with Intelligent Fleet Technology

The smart Transport Management System helps enterprises modernize logistics with real-time visibility, predictive

March 17, 2026

Katy Nichole Hits No. 1 At Radio With ‘Have Your Way’ From Sophomore Album, Honest Conversations

Katy Nichole Hits No. 1 At Radio With ‘Have Your Way’ From Sophomore Album, Honest Conversations

RIAA Platinum®-selling Artist Sings Her 4th #1 Song For Thousands Nightly As a Winter Jam 2026 Tour Headliner; Honest

March 17, 2026

ICONIX INTERNATIONAL AND REVLON ENTER INTO GLOBAL FRAGRANCE DEAL FOR FIRST-EVER SALT LIFE BRAND FRAGRANCE

ICONIX INTERNATIONAL AND REVLON ENTER INTO GLOBAL FRAGRANCE DEAL FOR FIRST-EVER SALT LIFE BRAND FRAGRANCE

NEW YORK, NY, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Iconix International Inc. has signed a global

March 17, 2026

REMAX DIRECTOR OF TRAINING JOINS GLOVER U COACHING BENCH

REMAX DIRECTOR OF TRAINING JOINS GLOVER U COACHING BENCH

REMAX Results Director of Training joins the fastest growing real estate coaching organization in North America. Shawna

March 17, 2026

Sasha’s Pet Resort Endorses March 23rd as National Puppy Day/Month in US and Canada

Sasha’s Pet Resort Endorses March 23rd as National Puppy Day/Month in US and Canada

Adopt puppies from shelters rather than buying from puppy mills where dogs endure cruel conditions for profit. We encourage puppy owners to celebrate by sharing…

March 17, 2026

Short, High-Frequency Travel Emerges as a New Trend Among Younger Generations

Short, High-Frequency Travel Emerges as a New Trend Among Younger Generations

With borders reopening and international flight networks fully recovering, the tourism market is undergoing a

March 17, 2026

Migration Consultations in Japan Hit Record High; Gunma Emerges as a Popular Destination

Migration Consultations in Japan Hit Record High; Gunma Emerges as a Popular Destination

Rising costs are driving more Japanese to consider moving to regional areas, with Gunma, Tochigi, and Nagano topping

March 17, 2026

2026 World Grand Prix Taipei Open – Who Will Rise to the Challenge and Battle in Taipei!

2026 World Grand Prix Taipei Open – Who Will Rise to the Challenge and Battle in Taipei!

TAIPEI, TAIWAN (MERXWIRE) – The Department of Sports, Taipei City Government and Taiwan Dancesport Development

March 17, 2026

Financial Times Ranks Spider Labs Among Fastest-Growing APAC Companies

Financial Times Ranks Spider Labs Among Fastest-Growing APAC Companies

Company reports 171% growth as demand rises for protection against ad fraud and fake leads TOKYO, JP / ACCESS Newswire

March 17, 2026

Red Wing Brings 120 Years Of Industry-Defining Craft To Work Apparel For The First Time

Red Wing Brings 120 Years Of Industry-Defining Craft To Work Apparel For The First Time

Engineered with the same comfort, durability, and style that define Red Wing boots RED WING, MN / ACCESS Newswire /

March 17, 2026

Cubic Secure Communications to Showcase Cubic(R) Vector(TM) Multi-Orbit Hybrid SATCOM Antenna at Satellite 2026

Cubic Secure Communications to Showcase Cubic(R) Vector(TM) Multi-Orbit Hybrid SATCOM Antenna at Satellite 2026

Enabling resilient, assured connectivity across SATCOM networks in contested electromagnetic spectrum environments SAN

March 17, 2026

Introducing Proda, the Lifestyle Protein-Infused Soda Launching Exclusively at Sprouts Farmers Market

Introducing Proda, the Lifestyle Protein-Infused Soda Launching Exclusively at Sprouts Farmers Market

Wellness Entrepreneur Matthew Postlethwaite Partners With Suja Co-Founder to Bring to Market the First Protein-Infused

March 17, 2026

A First-of-Its-Kind Video Game Based on Muslim Scientific Artifacts, Launching on March 20, 2026

A First-of-Its-Kind Video Game Based on Muslim Scientific Artifacts, Launching on March 20, 2026

Unity Productions Foundation Announces VANISHED: Puzzle Quest WASHINGTON, D.C. / ACCESS Newswire / March 17, 2026 /

March 17, 2026

Sauce Labs CEO, Prince Kohli, Says $1 Trillion Software Quality Industry Has Been “Building Wrong” for 20 Years

Sauce Labs CEO, Prince Kohli, Says $1 Trillion Software Quality Industry Has Been “Building Wrong” for 20 Years

The new Sauce AI for Test Authoring launch targets the most labor-intensive slice of the 22% of IT budgets spent on

March 17, 2026

Voxelmaps Launches Real-Time City Digital Twin for San José, Powered by NVIDIA AI

Voxelmaps Launches Real-Time City Digital Twin for San José, Powered by NVIDIA AI

Voxelmaps and NVIDIA partner to give city teams real-time 3D visibility into streets, infrastructure, and urban change

March 17, 2026

Signal Alchemy Expands Global Organic Ambient Roster with New Artists from Poland and Sweden

Signal Alchemy Expands Global Organic Ambient Roster with New Artists from Poland and Sweden

New signings Miaquirele and Broken Peak join an international roster of ambient artists spanning North America, South

March 17, 2026

ClubWorx named a 2025 Winner in the 7th Annual MXM Locations of Excellence Awards

ClubWorx named a 2025 Winner in the 7th Annual MXM Locations of Excellence Awards

ClubWorx, a fitness center in Fuquay-Varina, North Carolina, has been honored with an award for fitness facilities that

March 17, 2026

Azilen Technologies Becomes Merge Service Partner to Accelerate HRTech and HRIS Integrations

Azilen Technologies Becomes Merge Service Partner to Accelerate HRTech and HRIS Integrations

Azilen partners with Merge to accelerate HRTech and HRIS integrations for SaaS platforms with unified API-driven

March 17, 2026

Influential Women Features Kristi Ojala: Underground Mining Safety Leader and Industry Mentor

Influential Women Features Kristi Ojala: Underground Mining Safety Leader and Industry Mentor

ELKO, NV, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Safety Supervisor at Redpath USA Corporation Advancing

March 17, 2026

NJ Filmmaker Janice Molinari Premieres Inspiring Documentary Stronger Than You Think at Garden State Film Festival

NJ Filmmaker Janice Molinari Premieres Inspiring Documentary Stronger Than You Think at Garden State Film Festival

NJ filmmaker Janice Molinari premieres Stronger Than You Think at GSFF, telling Paralympian Ali Truwit’s powerful story

March 17, 2026

Rainbow Hill the Band Announces New Album Crash Bloom, Third Chapter of the ‘Brick by Brick’ Saga, Arriving March 20

Rainbow Hill the Band Announces New Album Crash Bloom, Third Chapter of the ‘Brick by Brick’ Saga, Arriving March 20

LOS ANGELES, CA, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Rainbow Hill the Band today announced the upcoming

March 17, 2026

FutureMoney and Halfmore Launch Generations Plan, Turning Household Work Into Roth IRA Savings for Kids

FutureMoney and Halfmore Launch Generations Plan, Turning Household Work Into Roth IRA Savings for Kids

New platform automates payroll, compliance, and Roth IRA investing — giving kids a head start on building generational

March 17, 2026

Camfil Featured in Manufacturing Marvels™ Showcasing Cleaner, Safer Operations

Camfil Featured in Manufacturing Marvels™ Showcasing Cleaner, Safer Operations

Video spotlights Jonesboro, Arkansas facility, ISO-certified processes and advanced air filtration innovations. Being

March 17, 2026

Elizabethtown Dental Assistant School to Open This Spring, Creating New Pathway into Dental Careers in Hardin County

Elizabethtown Dental Assistant School to Open This Spring, Creating New Pathway into Dental Careers in Hardin County

Elizabethtown Dental Assistant School will open this spring, offering a 12-week, hands-on dental assistant program in

March 17, 2026

Credera Releases New E-Book on Accelerating Insights in the ‘Age of Impatience’

Credera Releases New E-Book on Accelerating Insights in the ‘Age of Impatience’

DENVER, CO, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Credera, a global consulting firm specializing in

March 17, 2026

AllegroGraph 8.5 Strengthens the Semantic Foundation for Agentic AI

AllegroGraph 8.5 Strengthens the Semantic Foundation for Agentic AI

Franz Inc. expands graph, vector, and Neuro-Symbolic capabilities for enterprise-scale AI systems LAFAYETTE, CA, UNITED

March 17, 2026

Apellix Selects Drone Clean UK as Sole Distributor of Apellix Cleaning Drones in the UK

Apellix Selects Drone Clean UK as Sole Distributor of Apellix Cleaning Drones in the UK

Apellix selects Drone Clean UK as exclusive UK distributor for AI‑powered cleaning drones, boosting safety and

March 17, 2026

Techifox CEO Atul Sharma Named Among ’20 Most Inspiring CEOs to Watch in 2026′ for Driving Record Growth for Law Firms

Techifox CEO Atul Sharma Named Among ’20 Most Inspiring CEOs to Watch in 2026′ for Driving Record Growth for Law Firms

Recognition Highlights His Work Helping Law Firms Generate Over 100,000 Legal Leads and $350 Million in Case Value. The

March 17, 2026

WebWork Introduces a Time Clock Kiosk That Turns Any Device Into a Punch Clock

WebWork Introduces a Time Clock Kiosk That Turns Any Device Into a Punch Clock

With PIN-based clock-ins, break tracking, biometric verification, and real-time attendance, WebWork's kiosk turns any

March 17, 2026

Neuss-Based Digital Agency Digi-Workx Expands Service Offering to Help German SMEs Improve Online Visibility

Neuss-Based Digital Agency Digi-Workx Expands Service Offering to Help German SMEs Improve Online Visibility

Digi-Workx brings integrated web development and search engine optimization under one roof for small and medium-sized

March 17, 2026

Influential Women Features Tuesday L. Orluk: Founder of Blackfeather Healing Center

Influential Women Features Tuesday L. Orluk: Founder of Blackfeather Healing Center

HAMPTON FALLS, NH, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Guiding Holistic Wellness and Helping

March 17, 2026