PULSE NAME
Poisoning the well: AI supply chain attacks on Hugging Face and OpenClaw
WHITE AlienVault 2026-05-11 Modified: 2026-05-11
43
IOCs
MEDIUM VOLUME
Threat actors are actively exploiting AI distribution platforms like Hugging Face and ClawHub to deliver malware by embedding malicious code within models, datasets, and agent extensions. Over 575 malicious skills across 13 developer accounts were identified in the OpenClaw ecosystem, targeting Windows and macOS with trojans, cryptominers, and AMOS stealer. Attackers abuse trust relationships between users and AI platforms through indirect prompt injection, where hidden instructions cause AI agents to execute malicious actions on behalf of users. Trojanized skills masquerade as legitimate tools while instructing users to execute encoded commands or install hidden malicious dependencies. On Hugging Face, repositories host payloads within multistep infection chains disguised as legitimate applications. These campaigns employ social engineering, obfuscation, encryption, in-memory execution, process injection, and persistence techniques to evade detection while establishing covert command-and-control communica...
Indicators of Compromise (11 / 43 total)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0d2bb0876cc58d8b9c91686c019c131584f1b970 2026-05-11
FileHash-SHA1 197e0f42236143b60742ecbcac751617c22cfb9c 2026-05-11
FileHash-SHA1 1fc5e6458316277fae8272cbe9f3dfc86b681635 2026-05-11
FileHash-SHA1 5d253cc263851ec68c0a988bf86afbb3e9f0b491 2026-05-11
FileHash-SHA1 8bd284bfb607d5e970c88a69ca9422b44b1148a9 2026-05-11
FileHash-SHA1 92149d122dedb4e507e3a9cf6e43c53836e16fbe 2026-05-11
FileHash-SHA1 93b3d3925ccc201ab0f16017153a79ef05b8f5c2 2026-05-11
FileHash-SHA1 9f79b3301a88348bb6f03369c239a660a8c277bc 2026-05-11
FileHash-SHA1 a14bed1c46ba7406d5240e979251ccd394dfe3b5 2026-05-11
FileHash-SHA1 a396ec79d8e33ca984c7ffc7ee4d7d2caa8412ee 2026-05-11
FileHash-SHA1 a7c4407a7039102a8769bd51bfa64efc17943847 2026-05-11