PULSE NAME
Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer
WHITE AlienVault 2026-02-23 Modified: 2026-03-25
50
IOCs
MEDIUM VOLUME
A new campaign exploits OpenClaw skills to distribute the Atomic MacOS Stealer (AMOS). This evolution in supply chain attacks manipulates AI agentic workflows to install malware. The campaign spans multiple repositories with hundreds of malicious skills uploaded to ClawHub and SkillsMP. The infection chain begins with a seemingly harmless SKILL.md file that installs a prerequisite, leading to the download of a Mach-O universal binary. This AMOS variant steals extensive data, including credentials, browser data, cryptocurrency wallets, and various user documents. It lacks system persistence but expands its reach by exfiltrating Apple and KeePass keychains. The malware uses sophisticated encryption schemes and targets multiple browsers and cryptocurrency wallets.
Indicators of Compromise (10 / 50 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 125c5ca2b836cb46533cf690563528b8bd83a50f 2026-02-23
FileHash-SHA1 46a203240b7b06ec66058de2ab459d24c3545993 2026-02-23
FileHash-SHA1 71f101a613cc57745d4a605d0ce6d3c1cd7a4229 2026-02-23
FileHash-SHA1 8a5a5ff3663c4a530cfe975e66a0257f308368c6 2026-02-23
FileHash-SHA1 92a3d22717e6a7d25f74759dc9ec6f72e60c4f17 2026-02-23
FileHash-SHA1 93b3d3925ccc201ab0f16017153a79ef05b8f5c2 2026-02-23
FileHash-SHA1 a396ec79d8e33ca984c7ffc7ee4d7d2caa8412ee 2026-02-23
FileHash-SHA1 ac39f9b861a2c5829a4a841a0277763aa7acd84c 2026-02-23
FileHash-SHA1 c32d9638bc5c1249afc0ba5eac6ed5cc712b9df9 2026-02-23
FileHash-SHA1 f0ec6c8ac195ba88ef7f4e415d977a14d00acca2 2026-02-23