PULSE NAME
Poisoning the well: AI supply chain attacks on Hugging Face and OpenClaw
WHITE AlienVault 2026-05-11 Modified: 2026-05-11
43
IOCs
MEDIUM VOLUME
Threat actors are actively exploiting AI distribution platforms like Hugging Face and ClawHub to deliver malware by embedding malicious code within models, datasets, and agent extensions. Over 575 malicious skills across 13 developer accounts were identified in the OpenClaw ecosystem, targeting Windows and macOS with trojans, cryptominers, and AMOS stealer. Attackers abuse trust relationships between users and AI platforms through indirect prompt injection, where hidden instructions cause AI agents to execute malicious actions on behalf of users. Trojanized skills masquerade as legitimate tools while instructing users to execute encoded commands or install hidden malicious dependencies. On Hugging Face, repositories host payloads within multistep infection chains disguised as legitimate applications. These campaigns employ social engineering, obfuscation, encryption, in-memory execution, process injection, and persistence techniques to evade detection while establishing covert command-and-control communica...
Indicators of Compromise (11 / 43 total)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 31d36da3d6cd96f335b14a1dd1f06cc2 2026-05-11
FileHash-MD5 41f581f7d2c09ab0edfea850b9db506f 2026-05-11
FileHash-MD5 50eda29bfbeeb8b0429718447725016a 2026-05-11
FileHash-MD5 69315b7a1c4bf5ee56cba1de29d1761e 2026-05-11
FileHash-MD5 a37f6403fbf28fa0b48863287f4c5a5d 2026-05-11
FileHash-MD5 abae0f42f695e55714d362a088acc780 2026-05-11
FileHash-MD5 b488d8d0cb6ee18af9e5800b66ff1ed9 2026-05-11
FileHash-MD5 b6a77b7892ef22d6afd91eb980a3f3d8 2026-05-11
FileHash-MD5 bd46890121106b43f0c01ab82629400c 2026-05-11
FileHash-MD5 c5a53c02d531c5e46f9cc2fc0afbb88d 2026-05-11
FileHash-MD5 ce62d1b6116f34f9ba815db1e2016d2a 2026-05-11