This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

ApexaiQ Selects NWN as Strategic Partner to Deliver Unified IT Visibility and Cyber Resilience

ApexaiQ Selects NWN as Strategic Partner to Deliver Unified IT Visibility and Cyber Resilience

New partnership integrates ApexaiQ’s real-time asset intelligence with NWN’s industry-leading Experience Management

March 17, 2026

Genuine Optics Previews Quantum-Dot Optical Frequency Comb External Light Source for 3.2T/6.4T CPO

Genuine Optics Previews Quantum-Dot Optical Frequency Comb External Light Source for 3.2T/6.4T CPO

This solution reflects Genuine Optics’ strength in next-generation optical interconnects”— Genuine Optics CEO Madhav

March 17, 2026

Sofistic.AI Joins The Wealth Engineering Expert Sourcing Consortium

Sofistic.AI Joins The Wealth Engineering Expert Sourcing Consortium

The Wealth Engineering Family of Companies (WE) is pleased to announce the inclusion of Sofistic.AI as a core component

March 17, 2026

Smith Opens New Sales Office in Boston

Smith Opens New Sales Office in Boston

The new location will foster deep connections and drive innovation with both new and existing partners This strategic

March 17, 2026

World Champion Paddleboarder and Former Firefighter Launch New Chapter as Daytona Business Owners

World Champion Paddleboarder and Former Firefighter Launch New Chapter as Daytona Business Owners

Husband and Wife Team take the Helm at College HUNKS Hauling Junk & Moving DAYTONA, FL, UNITED STATES, March 17,

March 17, 2026

Let’s Roll Marketing LLC Announces Publication of Hermes-Echo and Warten Patent Applications

Let’s Roll Marketing LLC Announces Publication of Hermes-Echo and Warten Patent Applications

Two coordinated filings establish the session governance foundation of the SSOAR architecture for real-time distributed

March 17, 2026

Claw World Announces Details for Flagship Chinatown Grand Opening Celebration

Claw World Announces Details for Flagship Chinatown Grand Opening Celebration

Claw World arrives in Las Vegas Chinatown on March 28. The grand opening features $80,000 in prizes, cultural

March 17, 2026

Mitchell Moving & Storage Drives Local Growth With Focused 2026 Services in Olympia, Washington

Mitchell Moving & Storage Drives Local Growth With Focused 2026 Services in Olympia, Washington

Mitchell Moving & Storage enhances relocation services in Olympia, WA, offering streamlined solutions for residents

March 17, 2026

EDRM Congratulates Community Leaders Honored at the Legalweek Leaders in Tech Law Awards 2026

EDRM Congratulates Community Leaders Honored at the Legalweek Leaders in Tech Law Awards 2026

One trait they share is that all of them go beyond the requirements of their job to volunteer time to give back to our

March 17, 2026

Yasmin Levy Live in Miami

Yasmin Levy Live in Miami

Yasmin Levy Brings “One More Night with Yasmin Levy” to Miami I always feel that music is a bridge between hearts.

March 17, 2026

Jason Ruedy ‘The Home Loan Arranger’ Says Breckenridge Investors Use DSCR Loans to Consolidate Debt

Jason Ruedy ‘The Home Loan Arranger’ Says Breckenridge Investors Use DSCR Loans to Consolidate Debt

Breckenridge Mortgage Expert Jason Ruedy “The Home Loan Arranger” Says Real Estate Investors Are Using DSCR Loans to

March 17, 2026

Jason Ruedy ‘The Home Loan Arranger’ Says Investors Are Using DSCR Loans to Consolidate Debt and Grow Portfolios

Jason Ruedy ‘The Home Loan Arranger’ Says Investors Are Using DSCR Loans to Consolidate Debt and Grow Portfolios

Denver Mortgage Expert Jason Ruedy “The Home Loan Arranger” Says Real Estate Investors Are Using DSCR Loans to

March 17, 2026

Bri-Steel Manufacturing Celebrates Milestone: First 30-Inch STD Carbon Seamless Pipe Produced in the USA

Bri-Steel Manufacturing Celebrates Milestone: First 30-Inch STD Carbon Seamless Pipe Produced in the USA

Bri-Steel produces first-ever 30” STD carbon seamless pipe in USA history; now on display at historic Texas Pipe &

March 17, 2026

URLs.com Announces Strategic Partnership with .buzz Registry to Represent Premium Domain Inventory

URLs.com Announces Strategic Partnership with .buzz Registry to Represent Premium Domain Inventory

The new partnership expands access to premium .buzz domains and introduces innovative marketing of newly available

March 17, 2026

Tantalum Security Launches Unified Platform to Deliver Continuous AI & Expert-Driven Adversary Simulation Services

Tantalum Security Launches Unified Platform to Deliver Continuous AI & Expert-Driven Adversary Simulation Services

Cybersecurity veterans launch unified platform for continuous AI & expert-powered penetration testing, active

March 17, 2026

US Garage Door Heroes Offering $300 Off New Garage Door Installation in Scottsdale, AZ

US Garage Door Heroes Offering $300 Off New Garage Door Installation in Scottsdale, AZ

Scottsdale's top-rated garage door company is giving homeowners $300 off new garage door installation — available now

March 17, 2026

Box Tree Care Emphasizes Professional Stump Grinding and Comprehensive Tree Services for Property Safety

Box Tree Care Emphasizes Professional Stump Grinding and Comprehensive Tree Services for Property Safety

LEANDER, TX – March 17, 2026 – PRESSADVANTAGE – Box Tree Care, a professional tree service company serving the local

March 17, 2026

Grays LLC Unveils New Website and Streamlined Domain to Enhance HVAC Service Experience

Grays LLC Unveils New Website and Streamlined Domain to Enhance HVAC Service Experience

North Las Vegas, Nevada – March 17, 2026 – PRESSADVANTAGE – Grays LLC, a leading heating and cooling service provider

March 17, 2026

Court King Injury Law Addresses Rising Risks in Serious Auto Accident Injury Claims

Court King Injury Law Addresses Rising Risks in Serious Auto Accident Injury Claims

March 17, 2026 – PRESSADVANTAGE – Motor vehicle accidents continue to be a leading cause of serious injury across

March 17, 2026

Printbox London Introduces Expanded Same-Day Sticker and Label Printing Services Across North London

Printbox London Introduces Expanded Same-Day Sticker and Label Printing Services Across North London

March 17, 2026 – PRESSADVANTAGE – Printbox London (Same Day Printing London), a locally established print shop based in

March 17, 2026

SRH Landscapes LLC Announces Expanded Availability of Landscape Maintenance Services for Commercial and Government Properties Across Additional Texas Markets

SRH Landscapes LLC Announces Expanded Availability of Landscape Maintenance Services for Commercial and Government Properties Across Additional Texas Markets

DALLAS, TX – March 17, 2026 – PRESSADVANTAGE – SRH Landscapes LLC, a Texas-based landscaping firm with a long-standing

March 17, 2026

Washco Persian Rug Washing Announces Service Enhancements Across Sydney Operations

Washco Persian Rug Washing Announces Service Enhancements Across Sydney Operations

GREENACRE, NSW – March 17, 2026 – PRESSADVANTAGE – Washco Persian Rug Washing has announced a series of improvements

March 17, 2026

Future Green Irrigation Introduces Comprehensive Spring Irrigation Startup Program for 2026 Season

Future Green Irrigation Introduces Comprehensive Spring Irrigation Startup Program for 2026 Season

CALGARY, AB – March 17, 2026 – PRESSADVANTAGE – Future Green Irrigation has formally launched its 2026 spring

March 17, 2026

Malachi Gillihan, Trauma Specialist, Offers Integrative Trauma Recovery in Berkeley

Malachi Gillihan, Trauma Specialist, Offers Integrative Trauma Recovery in Berkeley

BERKELEY, CA – March 17, 2026 – PRESSADVANTAGE – Malachi Gillihan, Trauma Specialist, is a private practice based in

March 17, 2026

MidSolid Press & Pour Enhances Private Label Melt and Pour Soap Manufacturing Services to Meet Growing Demand for Custom Bulk Soap Production

MidSolid Press & Pour Enhances Private Label Melt and Pour Soap Manufacturing Services to Meet Growing Demand for Custom Bulk Soap Production

HIGHLANDS RANCH, CO – March 17, 2026 – PRESSADVANTAGE – MidSolid Press & Pour, a private-label soap manufacturer,

March 17, 2026

North Meridian Storage Announces Brand Release and Enhanced Security Features

North Meridian Storage Announces Brand Release and Enhanced Security Features

VALLEY CENTER, KS – March 17, 2026 – PRESSADVANTAGE – North Meridian Storage, a self-storage facility serving Valley

March 17, 2026

Perixx Launches PERIBOARD-535II Series, an Ergonomic Mechanical Keyboard with Low-Profile Switches and N-Key Rollover

Perixx Launches PERIBOARD-535II Series, an Ergonomic Mechanical Keyboard with Low-Profile Switches and N-Key Rollover

Perixx launches PERIBOARD-535II, a full-size ergonomic mechanical keyboard with low-profile switches, NKRO, and

March 17, 2026

Optima Office Launches Optima Insights to Connect Fragmented Business Systems and Deliver Real-Time Executive Visibility

Optima Office Launches Optima Insights to Connect Fragmented Business Systems and Deliver Real-Time Executive Visibility

New unified data infrastructure brings finance, payroll, timekeeping, marketing, and workforce data into one

March 17, 2026

Sikhs in Clinical Research Drives Health and Research Awareness Across the U.S. Sikh Community

Sikhs in Clinical Research Drives Health and Research Awareness Across the U.S. Sikh Community

LAKE ZURICH, IL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — The Sikh community in the United States, estimated

March 17, 2026

Jobs Keep Kids Out of Trouble: Robinson New Way Empowerment Youth Helps 93 Young Adults Secure Employment

Jobs Keep Kids Out of Trouble: Robinson New Way Empowerment Youth Helps 93 Young Adults Secure Employment

The organization partners with local businesses to teach personal and entrepreneurial skills while coordinating job

March 17, 2026

AGM Mobile Launches the AGM Legion 3 smartwatch: Premium AMOLED Display and Extreme Ruggedness Now Available

AGM Mobile Launches the AGM Legion 3 smartwatch: Premium AMOLED Display and Extreme Ruggedness Now Available

AGM Legion 3 – Unmatched Value in Rugged Smartwatches – AMOLED and other High-End Features at an Entry-Level Price NEW

March 17, 2026

Global Dairy Trade Completes 400th Auction as Platform Expands Role in Global Dairy Markets

Global Dairy Trade Completes 400th Auction as Platform Expands Role in Global Dairy Markets

Global Dairy Trade completes its 400th auction, marking nearly two decades as a key platform for global dairy price

March 17, 2026

Space Force Association Announces 2026 Scholarship Programs, Including New U.S. Space Force Guardian Scholarship

Space Force Association Announces 2026 Scholarship Programs, Including New U.S. Space Force Guardian Scholarship

COLORADO SPRINGS, CO, UNITED STATES, March 17, 2026 /EINPresswire.com/ — The Space Force Association (SFA) is proud to

March 17, 2026

SEO Vendor Secures Patent for Content Governance Architecture Required by AI Marketing Agents

SEO Vendor Secures Patent for Content Governance Architecture Required by AI Marketing Agents

SEO Vendor’s newly granted patent, the Dynamic Content Generation Method (US 12,572,752 B2), enables AI agents to

March 17, 2026

From Legacy to Leadership: Jiangsu University’s New Role in Global Agricultural Capacity Building

From Legacy to Leadership: Jiangsu University’s New Role in Global Agricultural Capacity Building

Building on its historic training legacy, Jiangsu University expands its global role in agricultural education and

March 17, 2026

Institute for Education Innovation Promotes Melissa Crawl to Vice President of Membership and Strategy

Institute for Education Innovation Promotes Melissa Crawl to Vice President of Membership and Strategy

Institute for Education Innovation Promotes Melissa Crawl to Vice President of Membership and Strategy NEW YORK, NY,

March 17, 2026

GlyMed+ Celebrates 35 Years of Innovation and Unwavering Commitment to the Skincare Professional

GlyMed+ Celebrates 35 Years of Innovation and Unwavering Commitment to the Skincare Professional

GlyMed+ marks 35 years of clinical mastery, supporting 100k+ professionals with pharmaceutical-grade formulas, advanced

March 17, 2026

Cambay Solutions Unveils AI-Accelerated Engineering Blueprint in Live Webinar

Cambay Solutions Unveils AI-Accelerated Engineering Blueprint in Live Webinar

Industry leaders to share dual perspective on technical integration and human adoption, providing a roadmap to move

March 17, 2026

Superior Capital Advisors Brokers Sale of 687-Unit, 3 Property Self Storage Portfolio in Charlotte, North Carolina

Superior Capital Advisors Brokers Sale of 687-Unit, 3 Property Self Storage Portfolio in Charlotte, North Carolina

This transaction is a testament to our expertise in the self storage industry and our ability to identify and connect

March 17, 2026

New iOS App Recaid Gives Professionals a Single Tool to Capture, Transcribe, and Summarize Live Sessions

New iOS App Recaid Gives Professionals a Single Tool to Capture, Transcribe, and Summarize Live Sessions

Zurich-based productivity app consolidates audio recording, slide capture, transcription, and AI summaries into a

March 17, 2026