This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

NEW MANAGEMENT BOOK: Creating a Joy-Centric Culture

NEW MANAGEMENT BOOK: Creating a Joy-Centric Culture

A Leader's Journey Through Dream, Believe, Dare, Do by Bill CapodagliVERO BEACH, Fla., Mar. 23, 2026 / PRZen /

March 24, 2026

Oola Bowls® Launches New Spring Menu Ahead of National Açaí Bowl Day, Building on Rapid National Growth

Oola Bowls® Launches New Spring Menu Ahead of National Açaí Bowl Day, Building on Rapid National Growth

We hear the same thing from customers everywhere. They want clean, better-for-you food that actually makes them feel good. That’s been the real driver behind…

March 24, 2026

Pantera Minerals Confirms High-Grade Antimony and Defines Multiple Drill Targets at Arkansas Project

Pantera Minerals Confirms High-Grade Antimony and Defines Multiple Drill Targets at Arkansas Project

First modern exploration delivers up to 3.92% Sb and large-scale soil anomalies, advancing Gillham toward maiden

March 24, 2026

Albany State University and Southern Regional Technical College Sign Agreement, Opening Pathway to Teaching Careers

Albany State University and Southern Regional Technical College Sign Agreement, Opening Pathway to Teaching Careers

Agreement Guarantees Credit Transfer for SRTC Students Pursuing a Bachelor of Science in Elementary Education at ASU

March 24, 2026

A Father’s Final Reflections Offer Love, Wisdom, and Life Lessons for Future Generations

A Father’s Final Reflections Offer Love, Wisdom, and Life Lessons for Future Generations

James Mavrinac shares a deeply personal and heartfelt collection of guidance, humor, and inspiration in A Pocket Guide

March 24, 2026

Veteran Home Investors Launches in Fort Wayne, Delivering Integrity-Driven Home Buying Solutions for Property Owners

Veteran Home Investors Launches in Fort Wayne, Delivering Integrity-Driven Home Buying Solutions for Property Owners

New company steps up with integrity business model for property owners and sellers FORT WAYNE , IN, UNITED STATES,

March 24, 2026

WildFire Storage Unveils maxRAID with Configurable Parity and 3M IOPS on 6 Drives

WildFire Storage Unveils maxRAID with Configurable Parity and 3M IOPS on 6 Drives

New architecture eliminates fixed RAID levels, supporting up to 1,023 parity drives while maintaining consistent

March 24, 2026

The Sacrifice of Lucinda Mills Uncovers a Shocking True-Inspired Story From Depression Era America

The Sacrifice of Lucinda Mills Uncovers a Shocking True-Inspired Story From Depression Era America

Author Naima Abdul Halim offers a powerful and deeply honest memoir in Because I Thought the Bridge Was the Solution: A

March 24, 2026

Dnotitia Launches Seahorse Cloud (SaaS) to Accelerate Enterprise AI Deployment with Advanced Data Preprocessing

Dnotitia Launches Seahorse Cloud (SaaS) to Accelerate Enterprise AI Deployment with Advanced Data Preprocessing

SEOUL, SOUTH KOREA, March 24, 2026 /EINPresswire.com/ — Dnotitia Inc. (Dnotitia), a company specializing in long-term

March 24, 2026

A Powerful Historical Work Honors the Lives and Losses of Negro League Baseball Figures

A Powerful Historical Work Honors the Lives and Losses of Negro League Baseball Figures

Chris Jensen delivers a deeply researched and moving account of players, pioneers, and untold stories in Tragedy in

March 24, 2026

Gym by Harley Expands Hotel Fitness Consultancy to More Than 230 Properties Worldwide

Gym by Harley Expands Hotel Fitness Consultancy to More Than 230 Properties Worldwide

Exercise physiologist Harley Pasternak brings evidence-based fitness facility design to luxury hospitality, with

March 24, 2026

Northern Spring Water Expands Operations with Move to New Glen Rock Facility

Northern Spring Water Expands Operations with Move to New Glen Rock Facility

GLEN ROCK, NJ – March 23, 2026 – PRESSADVANTAGE – Northern Spring Water, a regional provider of natural spring water

March 24, 2026

Zambuki SEO Company Expands to Tampa with Specialized Services for Home Improvement Sector

Zambuki SEO Company Expands to Tampa with Specialized Services for Home Improvement Sector

Saint Petersburg, Florida – March 23, 2026 – PRESSADVANTAGE – Zambuki, a digital marketing firm specializing in search

March 24, 2026

Liberty Renovation Johnson City Expands Custom Home Renovations to Meet Growing Demand

Liberty Renovation Johnson City Expands Custom Home Renovations to Meet Growing Demand

JOHNSON CITY, TN – March 23, 2026 – PRESSADVANTAGE – Liberty Renovation, a licensed general contractor serving the

March 24, 2026

Crumbl Launches Limited-Edition Easter Bundl, Making Holiday Celebrations Sweeter and Simpler

Crumbl Launches Limited-Edition Easter Bundl, Making Holiday Celebrations Sweeter and Simpler

PROVO, UT, UNITED STATES, March 23, 2026 /EINPresswire.com/ — Crumbl Launches Limited-Edition Easter Bundl, Making

March 23, 2026

Vetcon Electricians Ocala is Expanding Their Electrical Services in Marion Oaks, FL

Vetcon Electricians Ocala is Expanding Their Electrical Services in Marion Oaks, FL

Vetcon Electricians Ocala, Electrical Contractor, Emergency Panel Upgrade to Meet Growing Demand for Emergency Panel

March 23, 2026

Chris Cardillo Makes Music History with Dual-Genre Album Release

Chris Cardillo Makes Music History with Dual-Genre Album Release

SWEDESBORO, NJ, UNITED STATES, March 23, 2026 /EINPresswire.com/ — Jersey-bred musician, producer, and actor Chris

March 23, 2026

TradeWorX Leads Construction Industry in Health and Safety, Says ABC Report

TradeWorX Leads Construction Industry in Health and Safety, Says ABC Report

Providing OSHA-trained, safety-certified skilled trades professionals across construction, industrial, and energy

March 23, 2026

Atomic Wings Breaks Ground in Fort Worth: Multi-Unit Operator John Durik Leads Q2 Expansion Following Houston Surge

Atomic Wings Breaks Ground in Fort Worth: Multi-Unit Operator John Durik Leads Q2 Expansion Following Houston Surge

Atomic Wings fuels its Texas Triangle expansion as Area Developer Jalal Kapadia and Multi-Unit Operator John Durik

March 23, 2026

Scorpius Space Launch Company Appoints Aerospace Veteran Craig W. Schiffman as Strategy and Business Development Manager

Scorpius Space Launch Company Appoints Aerospace Veteran Craig W. Schiffman as Strategy and Business Development Manager

TORRANCE, CA, UNITED STATES, March 23, 2026 /EINPresswire.com/ — — Scorpius Space Launch Systems (SSLC) announced

March 23, 2026

Philly Fitness On Ridge Announces January 2026 Gym Membership Specials Including $10/Month Offer

Philly Fitness On Ridge Announces January 2026 Gym Membership Specials Including $10/Month Offer

PHILADELPHIA, PA – March 23, 2026 – PRESSADVANTAGE – Philly Fitness On Ridge announced new membership specials for January 2026 at its Philadelphia club, introducing…

March 23, 2026

ABRIDGED, PRELIMINARY AND UNAUDITED QUARTERLY AND FULL YEAR RESULTS AND DETAILS OF MANAGEMENT CONFERENCE Call for the Fourth Quarter and Full Year Ended December 31, 2025 (“The Quarter” or “Q4 2025” and “FY 2025” Respectively)

ABRIDGED, PRELIMINARY AND UNAUDITED QUARTERLY AND FULL YEAR RESULTS AND DETAILS OF MANAGEMENT CONFERENCE Call for the Fourth Quarter and Full Year Ended December 31, 2025 (“The Quarter” or “Q4 2025” and “FY 2025” Respectively)

RECORD FINANCIAL PERFORMANCE IN FY 2025, STRONG CASH GENERATION AND CLEAR GROWTH MOMENTUM INTO 2026 SAINT HELIER, JE / ACCESS Newswire / March 23, 2026…

March 23, 2026

Women Rising America Ignites a National Movement Through the Power of Women’s Stories

Women Rising America Ignites a National Movement Through the Power of Women’s Stories

ST. LOUIS, MO, UNITED STATES, March 23, 2026 /EINPresswire.com/ — Women Rising America is a groundbreaking female

March 23, 2026

Engel & Volkers Lists $4.2M Modern Colorado Estate in Berthoud

Engel & Volkers Lists $4.2M Modern Colorado Estate in Berthoud

Northern Colorado property features 7,772 SF of living space, reclaimed materials, enterprise-grade technology, and

March 23, 2026

PAWS Sanctuary Opposes Six Flags Discovery Kingdom White Tiger Cub Display and Conservation Claims

PAWS Sanctuary Opposes Six Flags Discovery Kingdom White Tiger Cub Display and Conservation Claims

Performing Animal Welfare Society opposes display of white tigers as outdated, inhumane, and inconsistent with

March 23, 2026

Karns & Karns Personal Injury and Accident Attorneys Open New Round Rock, TX Location

Karns & Karns Personal Injury and Accident Attorneys Open New Round Rock, TX Location

Family-owned trial firm brings elite 18-wheeler, commercial accident, and survivor advocacy to the Austin metroplex. Round Rock is a massive hub of activity and industry,…

March 23, 2026

New Orlando Psychiatry Clinic Expands Access to Advanced TMS Therapy for Depression and Anxiety

New Orlando Psychiatry Clinic Expands Access to Advanced TMS Therapy for Depression and Anxiety

Bringing innovative TMS therapy and patient-centered psychiatric care to improve depression and anxiety outcomes in

March 23, 2026

Phillips Law Group Attorney Montana Thompson Secures $316,500 Settlement in Avondale, AZ

Phillips Law Group Attorney Montana Thompson Secures $316,500 Settlement in Avondale, AZ

Avondale car accident attorney Montana Thompson of Phillips Law Group wins $316,500 for client injured in a red-light

March 23, 2026

Corporate First Aid and CPR Training Helps Reduce Risk and Control Costs

Corporate First Aid and CPR Training Helps Reduce Risk and Control Costs

March 23, 2026 – PRESSADVANTAGE – Cardinal Compliance Consultants announced an upcoming Adult First Aid, CPR, and AED

March 23, 2026

EAR Customized Hearing Protection Explains Why Professionals Choose Custom Over Universal Earplugs

EAR Customized Hearing Protection Explains Why Professionals Choose Custom Over Universal Earplugs

BOULDER, CO – March 23, 2026 – PRESSADVANTAGE – EAR Customized Hearing Protection today released educational guidance

March 23, 2026

Cachee.ai Introduces Autonomous Predictive Caching

Cachee.ai Introduces Autonomous Predictive Caching

New infrastructure category replaces the reactive caching model with AI that loads data before it’s requested Every caching product on the market today is fundamentally…

March 23, 2026

German Car Depot Expands Land Rover Repair Services in Aventura, FL, Addressing Growing Demand Across South Florida

German Car Depot Expands Land Rover Repair Services in Aventura, FL, Addressing Growing Demand Across South Florida

European specialist German Car Depot is meeting demand for Land Rover repair near Aventura, FL, offering dealer-level

March 23, 2026

Karns & Karns Personal Injury and Accident Attorneys Launch New Cerritos, CA Office

Karns & Karns Personal Injury and Accident Attorneys Launch New Cerritos, CA Office

Family-owned trial firm expands its Southern California presence with a specialized “Pivot” location focused on catastrophic accidents and survivor advocacy Cerritos is a vital economic…

March 23, 2026

Middle East Conflict Exposes America’s Aviation Fuel Vulnerability: XCF Global Highlights the Case for Domestic Sustainable Aviation Fuel

Middle East Conflict Exposes America’s Aviation Fuel Vulnerability: XCF Global Highlights the Case for Domestic Sustainable Aviation Fuel

SAF prices reached an all‑time high as global jet fuel markets tightened due to disruptions in the Strait of

March 23, 2026

XCF Global CEO Highlights Renewable Energy Security as Cornerstone of Scaling Sustainable Aviation Fuel at Advanced Bioeconomy Leadership Conference, ABLC2026

XCF Global CEO Highlights Renewable Energy Security as Cornerstone of Scaling Sustainable Aviation Fuel at Advanced Bioeconomy Leadership Conference, ABLC2026

HOUSTON, TX / ACCESS Newswire / March 23, 2026 / XCF Global, Inc. ("XCF") (Nasdaq:SAFX) a leading innovator in

March 23, 2026

Newsmax Appoints David Evans to Board of Directors

Newsmax Appoints David Evans to Board of Directors

Former CFO and COO Brings 25 Years of Public Company Financial and Operational LeadershipEvans Adds Digital Media

March 23, 2026

‘Villa One at Waiea’: One of One Five-Story Honolulu Penthouse to Sell at Auction

‘Villa One at Waiea’: One of One Five-Story Honolulu Penthouse to Sell at Auction

With a private pool, resort-style amenities, and sweeping ocean views, ‘Villa One at Waiea’ is the firm’s newest

March 23, 2026

Sunstone Digital Tech Enhances Customer Engagement With Strategic Text Message Marketing Services

Sunstone Digital Tech Enhances Customer Engagement With Strategic Text Message Marketing Services

Sunstone Digital Tech expands its digital marketing capabilities by delivering high-conversion text message marketing

March 23, 2026

Cortavo Receives 2026 Global Recognition Award for Excellence in Leadership and Mentorship in the MSP Industry

Cortavo Receives 2026 Global Recognition Award for Excellence in Leadership and Mentorship in the MSP Industry

The international award recognizes Cortavo’s structured mentorship programs and leadership framework that connect

March 23, 2026

Roc Property Managers Supports Property Owners in Pittsford, NY

Roc Property Managers Supports Property Owners in Pittsford, NY

Roc Property Managers Supports Property Owners in Pittsford, NY PITTSFORD, NY, UNITED STATES, March 23, 2026

March 23, 2026