This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Maxon Marks Its Official Entry Into the AEC Market With Its Real-Time Archviz Solution

Maxon Marks Its Official Entry Into the AEC Market With Its Real-Time Archviz Solution

Redshift for Vectorworks now available, Autodesk Revit® beta open for sign-ups, and Graphisoft Archicad releasing later

March 17, 2026

Allied Universal Granted Patent for Canine Air Cargo Screening Technology

Allied Universal Granted Patent for Canine Air Cargo Screening Technology

IRVINE, CA / ACCESS Newswire / March 17, 2026 / Allied Universal®, a leading security and facility services provider,

March 17, 2026

iTrustCapital Sees Momentum in 2026 as More People Turn to the Platform for Buying Physical Gold and Silver

iTrustCapital Sees Momentum in 2026 as More People Turn to the Platform for Buying Physical Gold and Silver

IRVINE, CA / ACCESS Newswire / March 17, 2026 / iTrustCapital is seeing steady growth in 2026 as more long-term

March 17, 2026

CityHall.Wedding Launched Expanded Guides Covering 28 U.S. Cities

CityHall.Wedding Launched Expanded Guides Covering 28 U.S. Cities

March 17, 2026 – PRESSADVANTAGE – City Hall Wedding announced today the launch of its completely rebuilt online

March 17, 2026

Nicolet Plastics Details Advanced Injection Molding Capabilities for Medical Applications

Nicolet Plastics Details Advanced Injection Molding Capabilities for Medical Applications

JACKSON, WI – March 17, 2026 – PRESSADVANTAGE – Nicolet Plastics announced continued focus and refinement of its

March 17, 2026

All Pro Gutter Guards Expands Service Line With Downspout Repair

All Pro Gutter Guards Expands Service Line With Downspout Repair

WILLOW GROVE, PA – March 17, 2026 – PRESSADVANTAGE – All Pro Gutter Guards has announced the expansion of its exterior

March 17, 2026

Local Real Estate Expert Launches Comprehensive TSMC Relocation Guide

Local Real Estate Expert Launches Comprehensive TSMC Relocation Guide

PHOENIX, AZ – March 17, 2026 – PRESSADVANTAGE – Dominion Group Properties, a Phoenix-based real estate agency serving

March 17, 2026

Siam Legal International Highlights Thailand Privilege Visa as Long-Term Residency Alternative to Golden Visa Thailand

Siam Legal International Highlights Thailand Privilege Visa as Long-Term Residency Alternative to Golden Visa Thailand

Bangkok, Thailand – March 17, 2026 – PRESSADVANTAGE – Siam Legal International, a government-authorized General Sales

March 17, 2026

Corporate Leaders Must Rethink Engagement with Civil Rights Organizations, New Advisory Says

Corporate Leaders Must Rethink Engagement with Civil Rights Organizations, New Advisory Says

New advisory from Phase 2 Consulting™ examines how corporate relationships with civil rights organizations influence

March 17, 2026

Survey: 81% of Workers More Likely to Move Abroad Than Two Years Ago

Survey: 81% of Workers More Likely to Move Abroad Than Two Years Ago

Study of workers in the U.S., UK, and Canada finds rising costs, job instability, and political uncertainty driving

March 17, 2026

Copper Moon Coffee Celebrates NASA’s Historic Artemis II Misson with New ‘Artemis II Lunar Reserve’ Roast

Copper Moon Coffee Celebrates NASA’s Historic Artemis II Misson with New ‘Artemis II Lunar Reserve’ Roast

Limited-Edition Coffee Honors Human Spaceflight and Milestone Achievements of Astronaut Scholars Artemis II Lunar

March 17, 2026

As Agentic Voice Adoption Surges, Cloudonix Earns Global Recognition

As Agentic Voice Adoption Surges, Cloudonix Earns Global Recognition

The Industry Asked. We Delivered. The Recognition Followed. Customers demand better ways to deploy voice AI in

March 17, 2026

ELM Construction’s Elliott Pike Named Chairman of NAHB Remodelers Council

ELM Construction’s Elliott Pike Named Chairman of NAHB Remodelers Council

Award-Winning Homewood Builder Continues to Shape National Remodeling Industry. HOMEWOOD, AL, UNITED STATES, March 17,

March 17, 2026

Hindu Swayamsevak Sangh USA Marks Black History Month 2026 with Community Programs Across the Country

Hindu Swayamsevak Sangh USA Marks Black History Month 2026 with Community Programs Across the Country

Community Dialogues and Educational Programs Foster Unity and Civic Engagement ROCKAWAY, NJ, UNITED STATES, March 17,

March 17, 2026

Pulsenmore Announces Full Year 2025 Earnings Conference Call

Pulsenmore Announces Full Year 2025 Earnings Conference Call

Pulsenmore Ltd. (NASDAQ, TASE: PLSM), a pioneer in home ultrasound technology, today announced that it will release its

March 17, 2026

Amazon #1 Best Seller Building Your Financial Fortress by Markus Heitkoetter Now Available as Audiobook on Audible

Amazon #1 Best Seller Building Your Financial Fortress by Markus Heitkoetter Now Available as Audiobook on Audible

Financial Freedom Guide Expands to Audiobook Format for Professionals Seeking a Systematic Approach to Investing

March 17, 2026

PSR Home Remodeling Expands Remodeling Services in Miami and South Florida

PSR Home Remodeling Expands Remodeling Services in Miami and South Florida

PSR Home Remodeling provides kitchen remodeling, bathroom renovation, and full home remodeling services for homeowners

March 17, 2026

Palm Holdings Ltd. (ADGM) Highlights Strong Global Demand for Its Premium Silver Bars

Palm Holdings Ltd. (ADGM) Highlights Strong Global Demand for Its Premium Silver Bars

Over the past several months alone, the company has sold more than 200 tons of silver, demonstrating sustained global

March 17, 2026

Ascension St. Vincent’s Treats 1,000th Patient with Pulsed Field Ablation for Atrial Fibrillation

Ascension St. Vincent’s Treats 1,000th Patient with Pulsed Field Ablation for Atrial Fibrillation

Pulsed field ablation allows us to treat AFib in a way that is minimally invasive, efficient and designed to enhance

March 17, 2026

SOLV Holdings Appoints Heather Kirby Lyions as Chief Legal Officer

SOLV Holdings Appoints Heather Kirby Lyions as Chief Legal Officer

Former Zimmer Biomet Leader to Steer Legal Strategy and Support Growth Across SOLV’s Portfolio Companies Her judgment,

March 17, 2026

STMicroelectronics’ single-chip buck converter packs 3A power for appliances and industrial loads

STMicroelectronics’ single-chip buck converter packs 3A power for appliances and industrial loads

Tiny footprint, low BOM, 93% efficiency, with light-load and noise-sensitive options STMicroelectronics

March 17, 2026

Shawn Isaac Receives ICMA Credentialed Manager Designation for Leadership Excellence

Shawn Isaac Receives ICMA Credentialed Manager Designation for Leadership Excellence

Shawn Isaac Recognized by ICMA for Leadership Excellence Leadership today requires integrity, accountability, and a

March 17, 2026

i3 Broadband Joins South Suburban Mayors & Managers Association to Deepen Collaboration With Local Government Leaders

i3 Broadband Joins South Suburban Mayors & Managers Association to Deepen Collaboration With Local Government Leaders

Membership Strengthens i3 Broadband’s Community Partnerships Across Chicago’s South Suburbs By joining SSMMA, we’re

March 17, 2026

VINTRE Named Most Widely Applied Adjuvant in California in 2025

VINTRE Named Most Widely Applied Adjuvant in California in 2025

California pesticide-use data shows VINTRE® as the most widely applied adjuvant in 2025, reflecting strong grower

March 17, 2026

FR Conversions Names Carlos Badallo as Vice President of Quality and Engineering

FR Conversions Names Carlos Badallo as Vice President of Quality and Engineering

I’m honored to join FR Conversions and be part of a team that’s focused on making essential vehicles more accessible to

March 17, 2026

Fast-Growing Brokerage ADT Realty Expands to 28 States While Emphasizing Agent Training Over Paid Leads

Fast-Growing Brokerage ADT Realty Expands to 28 States While Emphasizing Agent Training Over Paid Leads

ADT Realty expands to 28 states with launches in Wyoming and Montana while promoting agent training and sustainable

March 17, 2026

43% of Americans Want Tech Companies to Pay AI’s ‘Water Bill,’ New Study Shows

43% of Americans Want Tech Companies to Pay AI’s ‘Water Bill,’ New Study Shows

20 daily AI prompts use 400+ water bottles yearly. Gen Z is 24% more aware than Gen X of AI’s hidden water footprint,

March 17, 2026

haku Celebrates One Year New York Road Runners Partnership–Supporting Global Running Community

haku Celebrates One Year New York Road Runners Partnership–Supporting Global Running Community

haku powers registration, fundraising, memberships, and race-day operations across New York Road Runners’ events,

March 17, 2026

Southwest Science Transforms Modern Labs with Reliable, Cost-Effective Equipment

Southwest Science Transforms Modern Labs with Reliable, Cost-Effective Equipment

Southwest Science offers reliable personal laboratory centrifuge, centrifuge machine PRP, and medical centrifuge

March 17, 2026

Quantum Design Oxford and Florida State University’s MagLab Announce Strategic Partnership

Quantum Design Oxford and Florida State University’s MagLab Announce Strategic Partnership

Collaboration to Deliver Superconducting Magnets up to 30 Tesla Through this partnership with the MagLab, Quantum

March 17, 2026

Heroes Made Expands to Montana, Utah, and Idaho to Support Elementary Character Education

Heroes Made Expands to Montana, Utah, and Idaho to Support Elementary Character Education

Zero-prep platform helps elementary schools across the Mountain West build critical life skills, resilience, and

March 17, 2026

Craftsmanship and Material Standards Shape Modern Vehicle Protection

Craftsmanship and Material Standards Shape Modern Vehicle Protection

Advanced materials and expert craftsmanship are setting new standards in modern vehicle protection and long-lasting

March 17, 2026

Stelmo AI Launches at SXSW, Introduces Healthcare Recruitment Autopilot

Stelmo AI Launches at SXSW, Introduces Healthcare Recruitment Autopilot

Austin-based startup defines a new category with a platform that automates healthcare recruitment from first touch to

March 17, 2026

Do Not Count On AI Companies To Police Themselves, Litteral LLP Partners Warn

Do Not Count On AI Companies To Police Themselves, Litteral LLP Partners Warn

Attorneys propose framework for monitoring AI developers and protecting whistleblowers and consumers. AI will continue

March 17, 2026

Metal Ninja Studios Demonstrates Concept to Comic™ Model at MEGACON Orlando as Creator Success Stories Expand

Metal Ninja Studios Demonstrates Concept to Comic™ Model at MEGACON Orlando as Creator Success Stories Expand

Creator-first studio showcases completed client projects, expanding creator ecosystem, and growing industry presence at

March 17, 2026

Spring 2026 Brings Two Electricity Rate Increases for Illuminating Company Customers

Spring 2026 Brings Two Electricity Rate Increases for Illuminating Company Customers

Ohio's Illuminating Company PTC rate may rise twice before July. Cleveland customers could pay $37 more per month by

March 17, 2026

Tarps Plus Discusses the Expanding Use of Tarps in Infrastructure and Public Works

Tarps Plus Discusses the Expanding Use of Tarps in Infrastructure and Public Works

Tarps Plus outlines how durable tarp solutions support infrastructure upgrades, roadwork, municipal projects, and

March 17, 2026

Ink Different Tattoos Teams Up with Dark Horse Tattoo to Train Detroit’s Next Tattoo Artists

Ink Different Tattoos Teams Up with Dark Horse Tattoo to Train Detroit’s Next Tattoo Artists

Led by Award-Winning Artist and Ink Master Finalist Sebastian Murphy, the Program Brings Professional Tattoo Education

March 17, 2026

Wines of Charleston, A New Wine Tourism Startup Begins Crowdfunding & Seeks Additional Investment in 2026

Wines of Charleston, A New Wine Tourism Startup Begins Crowdfunding & Seeks Additional Investment in 2026

It is a customer-matching concept where bespoke wine-focused itineraries for travelers are curated to match consumers

March 17, 2026

American Bullion Announces Its 13th Annual Scholarship Program

American Bullion Announces Its 13th Annual Scholarship Program

$1,000 scholarship will be awarded to the selected, as American Bullion’s 2026 Essay Scholarship Award Winner. LOS

March 17, 2026