This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Keystone Marble & Granite Expands Showroom Services in PA & DE

Keystone Marble & Granite Expands Showroom Services in PA & DE

Keystone Marble & Granite expands showroom services in PA and DE, giving customers more access to premium stone options and expert design support. LANCASTER, PA,…

March 18, 2026

Metrovolo Launches Private AI Platform for Professional Services Firms

Metrovolo Launches Private AI Platform for Professional Services Firms

New managed service deploys AI on firm-controlled infrastructure, keeping sensitive client data away from outside AI

March 18, 2026

CHANTAL MCNEILY SELECTED AS TOP GLOBAL FINANCIAL EMPOWERMENT LEADER OF THE YEAR BY IAOTP

CHANTAL MCNEILY SELECTED AS TOP GLOBAL FINANCIAL EMPOWERMENT LEADER OF THE YEAR BY IAOTP

The International Association of Top Professionals (IAOTP) will honor Chantl McNeily at their annual awards gala in NYC

March 18, 2026

FAA’s Streamlined Part 91 Letters of Authorization Process Made Easier with Nimbl Guide

FAA’s Streamlined Part 91 Letters of Authorization Process Made Easier with Nimbl Guide

Guide Explains Benefits, Who Qualifies, and How to Submit Multiple Applications to Reduce Approval Timelines ROCKVILLE,

March 18, 2026

Eric Doctorow’s Imaginative PORTRAITS Book Now Available

Eric Doctorow’s Imaginative PORTRAITS Book Now Available

Book Imagines a Single Face Painted By History’s Greatest Painters Across Time and Imagined eras—from Pompeii to the

March 18, 2026

Haven Treatment Center Announces Milestone After Passing State Fire Inspection, Expanding Foster Care Bed Availability

Haven Treatment Center Announces Milestone After Passing State Fire Inspection, Expanding Foster Care Bed Availability

Haven Treatment Center Clears Key Safety Hurdle, Paving the Way for Expanded Foster Care Capacity VANCOUVER, WA, UNITED

March 18, 2026

MountainWest Capital Network Names Mary Crafts 2026 Entrepreneur of the Year

MountainWest Capital Network Names Mary Crafts 2026 Entrepreneur of the Year

MountainWest Capital Network (MWCN) proudly honored entrepreneur, author, and speaker Mary Crafts as the 2026

March 18, 2026

Wilder Ranch Community Underway in Teton Valley

Wilder Ranch Community Underway in Teton Valley

3,250-Acre Ranch Community on the Quiet Side of the Tetons I grew up coming to the Teton Valley with my family for pack

March 18, 2026

Sifter Solutions, Inc. Partners with Brookshire Brothers, Inc. to Support SNAP Waiver Compliance & Health-Focused Retail

Sifter Solutions, Inc. Partners with Brookshire Brothers, Inc. to Support SNAP Waiver Compliance & Health-Focused Retail

FOR IMMEDIATE RELEASE Ensuring our stores remain prepared for evolving SNAP waiver requirements while continuing to

March 18, 2026

Elvictor Group Announces Approval of Reverse Stock Split

Elvictor Group Announces Approval of Reverse Stock Split

ATTIKI, GREECE / ACCESS Newswire / March 18, 2026 / Elvictor Group Inc. (OTCID:ELVG) ("Elvictor" or the "Company"), a

March 18, 2026

Babytree Surrogacy Outlines the Complete Babytree Surrogacy Process for Intended Parents in California

Babytree Surrogacy Outlines the Complete Babytree Surrogacy Process for Intended Parents in California

March 18, 2026 – PRESSADVANTAGE – Babytree Surrogacy, a leading surrogacy agency in California, has published a

March 18, 2026

Precision Reloading Expands BoreTech Cleaning Products Selection for Firearm Maintenance

Precision Reloading Expands BoreTech Cleaning Products Selection for Firearm Maintenance

MITCHELL, SD – March 18, 2026 – PRESSADVANTAGE – Precision Reloading has expanded its inventory of professional-grade

March 18, 2026

IntroDrink Releases Comprehensive Guide on Natural Magnesium Supplementation for Swiss Health Consumers

IntroDrink Releases Comprehensive Guide on Natural Magnesium Supplementation for Swiss Health Consumers

Zurich, Zurich – March 18, 2026 – PRESSADVANTAGE – IntroDrink, a leading Swiss online retailer of premium natural

March 18, 2026

Amana Care Clinic Emphasizes Walk-In Medical Services for Muscatine Area Residents

Amana Care Clinic Emphasizes Walk-In Medical Services for Muscatine Area Residents

MUSCATINE, Iowa – March 18, 2026 – PRESSADVANTAGE – Amana Care Clinic – Muscatine continues to address the growing

March 18, 2026

Dr. Michael Alcée, Respected Psychologist and Author, Says Healing From OCD Begins With Understanding, Not Fear or Doubt

Dr. Michael Alcée, Respected Psychologist and Author, Says Healing From OCD Begins With Understanding, Not Fear or Doubt

The author of The Upside of OCD encourages people living with OCD to embrace who they are, rather than trying to erase

March 18, 2026

Sticky Brand Included in The Boston Globe’s list of New England’s Fastest Growing Companies 2026

Sticky Brand Included in The Boston Globe’s list of New England’s Fastest Growing Companies 2026

BURLINGTON, VT, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Sticky Brand is proud to announce its inclusion in

March 18, 2026

Straight-Leg Jeans Are Leading the New Era of Denim in 2026

Straight-Leg Jeans Are Leading the New Era of Denim in 2026

MIAMI, FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Denim is once again at the forefront of global fashion

March 18, 2026

Gillie and Marc Team Up with Sesame Street To Unveil New Public Art Collaboration at RXR’s 590 Madison Avenue on 3/20

Gillie and Marc Team Up with Sesame Street To Unveil New Public Art Collaboration at RXR’s 590 Madison Avenue on 3/20

The Nostalgic Official Unveiling Will Take Place at 590 Madison Avenue, In Midtown, On Friday, March 20, from 10 AM to

March 18, 2026

AMD Direct Highlights Outdoor Living Solutions at HPBExpo26 in New Orleans

AMD Direct Highlights Outdoor Living Solutions at HPBExpo26 in New Orleans

Summerset and TrueFlame products on display with live educational sessions and cooking tips HPBExpo gives us a focused

March 18, 2026

Heritage Signs & Displays Opens New Charlotte Headquarters

Heritage Signs & Displays Opens New Charlotte Headquarters

The 4-Acre Charlotte Campus Will Serve as HQ and Regional Production Facility for the Veteran-Led, Family-Owned Company

March 18, 2026

Sweet Briar Honored by Virginia General Assembly for 125 Years of Women’s Leadership

Sweet Briar Honored by Virginia General Assembly for 125 Years of Women’s Leadership

Virginia General Assembly honors Sweet Briar College on Women’s Colleges Day, celebrating 125 years of leadership and

March 18, 2026

A.I. Competitors Locking Down Infrastructure Deals, Mogin Law Analysis Shows

A.I. Competitors Locking Down Infrastructure Deals, Mogin Law Analysis Shows

Review of the Mogin Law A.I. Deal Table shows growing use of power generation, compute power and datacenter commitments

March 18, 2026

Climate Scientist Jonathan Foley Honored by American Association of Geographers

Climate Scientist Jonathan Foley Honored by American Association of Geographers

The AAG Confers its Top Honor, the Atlas Award, on Environmental Scientist Jonathan Foley, in San Francisco March 19 I

March 18, 2026

Techbridge Girls and Cloud Girls Launch Joint Fundraising Campaign to Expand Pathways for Girls in STEM

Techbridge Girls and Cloud Girls Launch Joint Fundraising Campaign to Expand Pathways for Girls in STEM

Techbridge Girls and Cloud Girls launch a joint fundraising campaign to support TBG’s work to reengineer STEM education

March 18, 2026

#1 B2B Podcast, The Travel Trends Podcast, Launches Season 7

#1 B2B Podcast, The Travel Trends Podcast, Launches Season 7

With Video and Celebrity Mentalist David Stryker This season is about understanding how the biggest decisions in travel

March 18, 2026

OK Tire Store & Service Investing in Minnesota and North Dakota

OK Tire Store & Service Investing in Minnesota and North Dakota

Fargo, ND — OK Tire Store & Service, commitment to community investment focused on workforce development,

March 18, 2026

ZyDoc Highlights AI + Human Hybrid Documentation Solution for Retina Practices at ASRS Business of Retina in Houston

ZyDoc Highlights AI + Human Hybrid Documentation Solution for Retina Practices at ASRS Business of Retina in Houston

ZyDoc will showcase its AI documentation platform at ASRS 2026, offering a secure U.S.-based alternative that boosts

March 18, 2026

Lightspeed Systems Enhances Student Safety Platform with Emoji Detection Capability

Lightspeed Systems Enhances Student Safety Platform with Emoji Detection Capability

Lightspeed Alert Now Identifies Violence and Self-Harm Signals Expressed Through Emojis, Closing a Critical Gap in

March 18, 2026

Moment of Clarity Publishes New Resource on Using TMS for Depression Recovery

Moment of Clarity Publishes New Resource on Using TMS for Depression Recovery

Oceanside, CA – March 18, 2026 – PRESSADVANTAGE – Moment of Clarity has released a new educational resource examining

March 18, 2026

Big Easy Paver Patios Expands Outdoor Accessory Services with Addition of Somfy Smart Automation Products

Big Easy Paver Patios Expands Outdoor Accessory Services with Addition of Somfy Smart Automation Products

NEW ORLEANS, LA – March 18, 2026 – PRESSADVANTAGE – Big Easy Paver Patios, an outdoor construction and landscaping

March 18, 2026

Ginza Diamond Shiraishi Hong Kong Highlights Engagement Ring Craftsmanship, Structural Design, and Diamond Standards

Ginza Diamond Shiraishi Hong Kong Highlights Engagement Ring Craftsmanship, Structural Design, and Diamond Standards

Causeway Bay, HK – March 18, 2026 – PRESSADVANTAGE – Ginza Diamond Shiraishi Hong Kong has issued an official statement

March 18, 2026

Adjustable Dumbbells Full Set for Sale Launched for Home Fitness Enthusiasts by Strongway Gym Supplies

Adjustable Dumbbells Full Set for Sale Launched for Home Fitness Enthusiasts by Strongway Gym Supplies

Coventry, UK – March 18, 2026 – PRESSADVANTAGE – Strongway Gym Supplies has announced the launch of its updated range

March 18, 2026

Tommies Plumbing Johnson City Announces Enhanced Winter Emergency Response Services

Tommies Plumbing Johnson City Announces Enhanced Winter Emergency Response Services

March 18, 2026 – PRESSADVANTAGE – Tommies Plumbing Johnson City announces expanded emergency response protocols for

March 18, 2026

Press Advantage Reveals How Media Citations Are Becoming the Most Powerful Trust Signal for AI Brand Recommendations

Press Advantage Reveals How Media Citations Are Becoming the Most Powerful Trust Signal for AI Brand Recommendations

Las Vegas, NV – March 18, 2026 – PRESSADVANTAGE – Press Advantage, a leading press release distribution service,

March 18, 2026

RestoPros of Boise and Treasure Valley Shares Essential Frozen Pipe Prevention Tips for Homeowners

RestoPros of Boise and Treasure Valley Shares Essential Frozen Pipe Prevention Tips for Homeowners

MERIDIAN, ID – March 18, 2026 – PRESSADVANTAGE – RestoPros of Boise and Treasure Valley, a leading restoration services

March 18, 2026

Distinguished News Leader Stephen Capus to be Honored with Lifetime Achievement Award at NYF’s Storytellers Gala

Distinguished News Leader Stephen Capus to be Honored with Lifetime Achievement Award at NYF’s Storytellers Gala

New York Festivals Storytellers Gala Celebrates Its Legacy of Honoring Industry Visionaries It is a profound honor to

March 18, 2026

Dream Air Begins Construction on Corporate Aviation Facility at New Century AirCenter

Dream Air Begins Construction on Corporate Aviation Facility at New Century AirCenter

When owners can visit multiple facilities or markets in a single day, the aircraft becomes a business tool rather than

March 18, 2026

Aerolib Launches AI-Powered Mobile Ecosystem to Revolutionize Hospital Revenue Cycle and Denial Management

Aerolib Launches AI-Powered Mobile Ecosystem to Revolutionize Hospital Revenue Cycle and Denial Management

Aerolib launches Aerolib.app for Physician Advisors, featuring P2P simulations, IP-only search tools, & real-time

March 18, 2026

Manufacturers Shift to Circular Models as Demand for Reuse and Repair Climbs

Manufacturers Shift to Circular Models as Demand for Reuse and Repair Climbs

TULSA, OK, UNITED STATES, March 18, 2026 /EINPresswire.com/ — In order to preserve resources and reduce costs,

March 18, 2026

Pre-Orders Open March 17 for ‘The Joker (Concept Design by Lee Bermejo)’ 1/4 Scale Statue.

Pre-Orders Open March 17 for ‘The Joker (Concept Design by Lee Bermejo)’ 1/4 Scale Statue.

Prime 1 Studio announced “The Joker (Concept Design by Lee Bermejo)” 1/4 Scale Statue. Pre-orders began March 17, 2026 (JST), with release set for October…

March 18, 2026