PULSE NAME
341 Malicious Clawed Skills Found by the Bot They Were Targeting
WHITE ClawHavoc AlienVault 2026-02-04 Modified: 2026-03-06
17
IOCs
MEDIUM VOLUME
A massive malware campaign dubbed ClawHavoc has been uncovered in the ClawHub marketplace, targeting OpenClaw bots and their users. An AI bot named Alex, working with security researcher Oren Yomtov, discovered 341 malicious skills, including 335 from a single campaign. The malware, identified as Atomic Stealer (AMOS), uses sophisticated techniques to evade detection and steal sensitive data. The attack exploits users' trust in AI assistants, potentially compromising personal and financial information. In response, a new tool called Clawdex has been developed to help bots and users scan for malicious skills before installation.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Atomic Stealer (AMOS)
Indicators of Compromise (3 / 17 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0c76e33ddde228e9ce098edf3bf5f06a 2026-02-04
FileHash-MD5 3a4450bacf20eea2dcc246da7bce9667 2026-02-04
FileHash-MD5 8611dfd731c27ac1592de60a31c66634 2026-02-04