This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

TuxCare to Feature Extended Lifecycle Support for Open-Source Software at CloudFest 2026

TuxCare to Feature Extended Lifecycle Support for Open-Source Software at CloudFest 2026

PALO ALTO, CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — TuxCare, a global innovator in securing open source,

March 18, 2026

The Engagement Gap: Most Websites Lose Users After Just 56 Seconds

The Engagement Gap: Most Websites Lose Users After Just 56 Seconds

Riddle Marketing Report 2025 Reveals Interactive Formats Transform User Attention and Data Quality Interactive

March 18, 2026

Divine Kailash Announces Kailash Manasarovar Yatra 2026 by Road, Helicopter and Nepalgunj Route Pilgrimage Packages

Divine Kailash Announces Kailash Manasarovar Yatra 2026 by Road, Helicopter and Nepalgunj Route Pilgrimage Packages

Leading spiritual travel company unveils three carefully crafted pilgrimage routes for the holy Kailash Manasarovar

March 18, 2026

MMCG releases Comprehensive Multifamily Market Report as $162 Billion Loan Maturity Wall Looms Over Apartment Sector

MMCG releases Comprehensive Multifamily Market Report as $162 Billion Loan Maturity Wall Looms Over Apartment Sector

SAN FRANCISCO, CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — MMCG Invest, LLC, a commercial real estate

March 18, 2026

CoStar Group Recognizes Cravey Real Estate Services with 2025 Power Broker Awards

CoStar Group Recognizes Cravey Real Estate Services with 2025 Power Broker Awards

CORPUS CHRISTI, TX, UNITED STATES, March 18, 2026 /EINPresswire.com/ — CoStar Group (NASDAQ: CSGP), the premier

March 18, 2026

Your menu now talks back: QRCodeKIT launches AI-powered conversational QR menus for hospitality venues worldwide

Your menu now talks back: QRCodeKIT launches AI-powered conversational QR menus for hospitality venues worldwide

With a single activation, any QR menu becomes an assistant that instantly answers guest questions. If you already have

March 18, 2026

City of Decatur Introduces ‘Decatur Direct’ a New AI Chatbot Powered by Ordinal Connect

City of Decatur Introduces ‘Decatur Direct’ a New AI Chatbot Powered by Ordinal Connect

Government AI chatbot improves public access to city services while reducing the call and email load on City staff. Our

March 18, 2026

Healthcare Practices Prepare for Busy Season with Virtual Receptionist Coverage

Healthcare Practices Prepare for Busy Season with Virtual Receptionist Coverage

Industry data shows patient access challenges and workforce strain intensify during high-volume periods The busy season

March 18, 2026

Dr. Shameka Jones, of VeraRosa Higher Education Scholarship, Selected to Georgia Financial Educators Council Board

Dr. Shameka Jones, of VeraRosa Higher Education Scholarship, Selected to Georgia Financial Educators Council Board

Dr. Shameka Jones proves that financial wellness is a foundation for physical and community health.”— Vince Shorb, CEO,

March 18, 2026

SGS launches SGS Nexus – a new global food intelligence platform

SGS launches SGS Nexus – a new global food intelligence platform

New digital platform combines regulatory intelligence, food safety analytics and AI-driven risk detection With SGS

March 18, 2026

CytoNiche’s 3D FloTrix™ Platform Wins ‘Emerging Bioprocessing Supplier Award’ at ABEA 2026

CytoNiche’s 3D FloTrix™ Platform Wins ‘Emerging Bioprocessing Supplier Award’ at ABEA 2026

CytoNiche’s 3D FloTrix™ platform won the Emerging Bioprocessing Supplier – Downstream award at ABEA 2026, recognising

March 18, 2026

Aiarty Image Enhancer Advances Realism in AI Image Enhancement with High-Fidelity Results

Aiarty Image Enhancer Advances Realism in AI Image Enhancement with High-Fidelity Results

Aiarty Image Enhancer addresses concerns over the waxy AI look, delivering natural, high-fidelity image enhancement

March 18, 2026

env zero and CloudQuery Announce Merger to Create the Industry’s First Unified Cloud Intelligence Platform

env zero and CloudQuery Announce Merger to Create the Industry’s First Unified Cloud Intelligence Platform

BOSTON, MA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — env zero (envzero.com), the leader in Infrastructure as

March 18, 2026

United Planet Showcases the Future of Global Education at The Forum on Education Abroad

United Planet Showcases the Future of Global Education at The Forum on Education Abroad

United Planet highlights service-learning, global internships, and new college credit pathways at a leading global

March 18, 2026

NASHVILLE DANCE FEST RETURNS TO MUSIC CITY – SEPTEMBER 4 – 6, 2026

NASHVILLE DANCE FEST RETURNS TO MUSIC CITY – SEPTEMBER 4 – 6, 2026

Labor Day Weekend Event Boasts Eight Dance Floors, Competitive Dancing and Live Music Stages with Emerging Nashville

March 18, 2026

Ringover Launches Enhanced AI Assistant, Ask Empower 2.0

Ringover Launches Enhanced AI Assistant, Ask Empower 2.0

Unified comms platform adds to its native conversational AI capability, from individual call transcript analysis to

March 18, 2026

MedArrive Acquires Key Assets from Inbound Health to Expand Home Care Operations Platform

MedArrive Acquires Key Assets from Inbound Health to Expand Home Care Operations Platform

Acquisition expands MedArrive’s presence in home care market and adds patient navigation capabilities; health-tech

March 18, 2026

Charter Oak State College School of Education offers April Open House (via Zoom)

Charter Oak State College School of Education offers April Open House (via Zoom)

Online Undergraduate, Graduate, and Certificate Programs for Early Childhood Education Professionals NEW BRITAIN, CT,

March 18, 2026

Roquemore Skierski PLLC Expands Commercial Litigation, Real Estate Practices with Addition of Veteran Litigation Lawyers

Roquemore Skierski PLLC Expands Commercial Litigation, Real Estate Practices with Addition of Veteran Litigation Lawyers

Two highly experienced business and commercial litigation attorneys have joined the Dallas law firm Roquemore Skierski

March 18, 2026

American Academy of Pediatrics Launches New PREP Program on mon`k LMS by Impelsys

American Academy of Pediatrics Launches New PREP Program on mon`k LMS by Impelsys

Impelsys’ moǹk LMS goes live for AAP, enabling scalable, data-driven pediatric education with interactive content,

March 18, 2026

Physician-Led AI Health Coach Platform Aims to Transform Community-Based Healthcare Delivery

Physician-Led AI Health Coach Platform Aims to Transform Community-Based Healthcare Delivery

Affordable, integrated solution designed to improve patient outcomes, reduce administrative burden, and sustain

March 18, 2026

Sandfly Security and Carahsoft Partner to Bring Agentless Linux EDR to the Public Sector

Sandfly Security and Carahsoft Partner to Bring Agentless Linux EDR to the Public Sector

Agentless Linux Security Now Available to Government Agencies and Critical Infrastructure Operators Sandfly's agentless

March 18, 2026

AlmaLinux Day: Germany Event To Take Place March 26

AlmaLinux Day: Germany Event To Take Place March 26

FORT MYERS, FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — The AlmaLinux OS Foundation, a nonprofit that

March 18, 2026

Christopher Riegg Announces Jeffrey Van Straten Joins Promontory Strategy Group to Support Midwest Family Businesses

Christopher Riegg Announces Jeffrey Van Straten Joins Promontory Strategy Group to Support Midwest Family Businesses

Experienced executive leader to support strategic and pre-transaction advisory services for privately held and

March 18, 2026

McKenzie Law Firm, P.C. Announces 2025 Teen Drinking and Driving Prevention PSA Scholarship Winner

McKenzie Law Firm, P.C. Announces 2025 Teen Drinking and Driving Prevention PSA Scholarship Winner

McKenzie Law Firm announces Amari Bailey as the 2025 Teen Drinking and Driving Prevention PSA Scholarship winner,

March 18, 2026

GetEducated Surpasses 35,000 Online Degrees, Creating One of the Web’s Largest Directories of Accredited Online Programs

GetEducated Surpasses 35,000 Online Degrees, Creating One of the Web’s Largest Directories of Accredited Online Programs

Milestone highlights the explosive growth of online education and gives students a powerful tool to compare thousands

March 18, 2026

Turn1 Unveils 2025–2026 Performance Upgrades for Ducati, Aprilia, and BMW Motorcycles

Turn1 Unveils 2025–2026 Performance Upgrades for Ducati, Aprilia, and BMW Motorcycles

Premium carbon fiber components designed to improve performance, style, and the overall riding experience Turn1

March 18, 2026

AI Energy Conference 3 to Highlight AI-Driven Energy and Data Center Growth Across the Appalachian Basin

AI Energy Conference 3 to Highlight AI-Driven Energy and Data Center Growth Across the Appalachian Basin

AI Energy Conference 3 is designed to give companies the actionable information they need to participate in this

March 18, 2026

MoodRx LLC Expands Insurance Coverage and Specialized Mental Health Services Across Pennsylvania

MoodRx LLC Expands Insurance Coverage and Specialized Mental Health Services Across Pennsylvania

Expanding coverage, lowering costs, and age-specific therapy models—MoodRx is redefining how Pennsylvanians access

March 18, 2026

Adoption of HOA Start’s Communications Suite Grows as Boards Modernize Resident Communication

Adoption of HOA Start’s Communications Suite Grows as Boards Modernize Resident Communication

As more associations adopt digital communication tools, boards reach residents faster, reducing missed messages, and

March 18, 2026

Waratek Redefines Secure Development with Launch of Waratek IAST at JavaOne 2026

Waratek Redefines Secure Development with Launch of Waratek IAST at JavaOne 2026

AI-assisted code speeds development, but introduces vulnerabilities at an alarming rate. Waratek IAST reports flaws

March 18, 2026

Whey Water Announces May 2026 Launch of Sparkling Protein Beverage

Whey Water Announces May 2026 Launch of Sparkling Protein Beverage

Launching in May 2026, Whey Water offers 18g whey protein isolate per can, sweetened with stevia and monk fruit, with

March 18, 2026

Independent Film DARKLIGHT Launches on Seed&Spark Exploring Identity and Transformation

Independent Film DARKLIGHT Launches on Seed&Spark Exploring Identity and Transformation

An independent film project using cinematic storytelling to explore identity, transformation, and emotional depth. LOS

March 18, 2026

New Survey Reveals Most Homeowners Are Leaving Valuable Jewelry Underprotected

New Survey Reveals Most Homeowners Are Leaving Valuable Jewelry Underprotected

BriteCo Research Shows Widespread Misunderstanding About Jewelry Coverage in Homeowners Insurance Policies Many

March 18, 2026

ProHance Launches Comprehensive Global Productivity Benchmarking Report Based on Three-Year Data Set

ProHance Launches Comprehensive Global Productivity Benchmarking Report Based on Three-Year Data Set

Reveals key productivity benchmarks, workforce trends, and actionable insights to help enterprises optimize performance

March 18, 2026

Medicus Pharma To Discuss Positive Skinject(R) Phase 2 Topline Results In Fireside Chat Hosted By Brookline Capital Markets Biotechnology Equity Research Analyst

Medicus Pharma To Discuss Positive Skinject(R) Phase 2 Topline Results In Fireside Chat Hosted By Brookline Capital Markets Biotechnology Equity Research Analyst

Phase 2 Study Demonstrated 73% clinical Clearance in the 200-µg Arm suggests that ~3 out of 4 treated lesions may allow

March 18, 2026

Nextech3D.ai Division Achieves Profitability, Signaling Operating Leverage, Margin Expansion and Accelerating Enterprise Momentum

Nextech3D.ai Division Achieves Profitability, Signaling Operating Leverage, Margin Expansion and Accelerating Enterprise Momentum

First Full Month of Post-Acquisition Profitability Highlights Platform Scale, Improving Margins and a Clear Path Toward

March 18, 2026

TGI Solar Power Group Inc. Announces Strategic Alliance With MetaSense Inc. to Scale Human Capital for Global Energy and Technology Projects

TGI Solar Power Group Inc. Announces Strategic Alliance With MetaSense Inc. to Scale Human Capital for Global Energy and Technology Projects

Redefining Human Capital Management Across Aviation, Nuclear Power, AI, Robotics and Agentic AI MIAMI, FL / ACCESS

March 18, 2026

#paid and Pinterest Announce Strategic Partnership to Power Creator-Led Commerce at the Moment of Decision

#paid and Pinterest Announce Strategic Partnership to Power Creator-Led Commerce at the Moment of Decision

New Partnership Connects Brands With Consumers at the Point of Decision Through Creator-Led Media SAN FRANCISCO, CA AND

March 18, 2026

App Orchid Enables Role-based Control of LLMs in Agentic BI

App Orchid Enables Role-based Control of LLMs in Agentic BI

New release introduces role-based AI guardrails and mobile Easy Answers experience SAN RAMON, CA / ACCESS Newswire /

March 18, 2026