PULSE NAME
Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer
WHITE AlienVault 2026-02-23 Modified: 2026-03-25
50
IOCs
MEDIUM VOLUME
A new campaign exploits OpenClaw skills to distribute the Atomic MacOS Stealer (AMOS). This evolution in supply chain attacks manipulates AI agentic workflows to install malware. The campaign spans multiple repositories with hundreds of malicious skills uploaded to ClawHub and SkillsMP. The infection chain begins with a seemingly harmless SKILL.md file that installs a prerequisite, leading to the download of a Mach-O universal binary. This AMOS variant steals extensive data, including credentials, browser data, cryptocurrency wallets, and various user documents. It lacks system persistence but expands its reach by exfiltrating Apple and KeePass keychains. The malware uses sophisticated encryption schemes and targets multiple browsers and cryptocurrency wallets.
Indicators of Compromise (10 / 50 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0c76e33ddde228e9ce098edf3bf5f06a 2026-02-23
FileHash-MD5 760c89959e2d80f9b78a320023a875b7 2026-02-23
FileHash-MD5 80ab5ba94b8b4d135453f8cb58be209d 2026-02-23
FileHash-MD5 8611dfd731c27ac1592de60a31c66634 2026-02-23
FileHash-MD5 a37f6403fbf28fa0b48863287f4c5a5d 2026-02-23
FileHash-MD5 a6d19622c8961b781901baec4ab599de 2026-02-23
FileHash-MD5 a8ad1697e8c8823ac7b77557bcb85a24 2026-02-23
FileHash-MD5 b488d8d0cb6ee18af9e5800b66ff1ed9 2026-02-23
FileHash-MD5 b8f295977d4dec2e9bffd6fce2320bd1 2026-02-23
FileHash-MD5 d8ba368e60477651ffb04e8e4f93509b 2026-02-23