This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

High-Resolution Airborne Survey Completed at Music Valley HREE Project

High-Resolution Airborne Survey Completed at Music Valley HREE Project

Mapping and sampling underway to refine geological model SAN BERNARDINO, CA / ACCESS Newswire / March 17, 2026 /

March 17, 2026

TRNR Exhibits at HFA 2026 with All Four Brands and Strong Leadership Presence

TRNR Exhibits at HFA 2026 with All Four Brands and Strong Leadership Presence

TRNR Now Operates Four Premium Fitness Brands Following Acquisition of Ergatta, Leading to Increased Guidance of more

March 17, 2026

Regentis Biomaterials Develops and Patents New Solvent-Free Manufacturing Process That Increases GelrinC Production Yield by 400%

Regentis Biomaterials Develops and Patents New Solvent-Free Manufacturing Process That Increases GelrinC Production Yield by 400%

Breakthrough manufacturing process comes in preparation for upcoming commercial launch in Europe planned for later this

March 17, 2026

Aspire Biopharma’s Subsidiary, Buzz Bomb Caffeine Company, Appoints John Choe as Western Sales Director

Aspire Biopharma’s Subsidiary, Buzz Bomb Caffeine Company, Appoints John Choe as Western Sales Director

ESTERO, FL / ACCESS Newswire / March 17, 2026 / Aspire Biopharma Holdings, Inc. (Nasdaq:ASBP) ("Aspire"), wholly owned

March 17, 2026

Influential Women Profiles Nikita Bhosale: Driving Excellence in Global Supply Chain Operations

Influential Women Profiles Nikita Bhosale: Driving Excellence in Global Supply Chain Operations

LITTLE FALLS, NJ, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Senior Product Supply Project Manager at Bayer

March 17, 2026

Levinson Axelrod Expands Presence in South Jersey With New Cherry Hill Office

Levinson Axelrod Expands Presence in South Jersey With New Cherry Hill Office

New location brings the firm’s 86+ years of courtroom-first advocacy closer to families across Camden County and

March 17, 2026

Polar Data Centers and Vertiv win ‘Most Successfully Delivered Data Centre’ award.

Polar Data Centers and Vertiv win ‘Most Successfully Delivered Data Centre’ award.

DCW award recognizes the successful delivery of DRA01, a 12MW next-generation AI-ready facility in Norway. This award

March 17, 2026

Influential Women Profiles Linda (Lily) Filippi: Trusted Medicare Specialist Serving Maine and Vermont

Influential Women Profiles Linda (Lily) Filippi: Trusted Medicare Specialist Serving Maine and Vermont

THOMASTON, ME, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Owner of Medicare Plan Solutions, LLC, Empowers

March 17, 2026

Influential Women Spotlights Mia Fontanarosa: Respected Leader and Advocate in Cognitive Healthcare

Influential Women Spotlights Mia Fontanarosa: Respected Leader and Advocate in Cognitive Healthcare

FORT WORTH, TX, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Senior Account Executive at Cognivue, Inc. Combines

March 17, 2026

G.O.L.T.® STAR Certification for AI-powered Contract Intelligence Platform

G.O.L.T.® STAR Certification for AI-powered Contract Intelligence Platform

RECITAL certified by TRANSFORMING.LEGAL as G.O.L.T.® STAR Legal teams are struggling with the absence of independent

March 17, 2026

LDSK and BlueZoo Partner to Deliver Unprecedented Accuracy and Audience Targeting for DOOH and Retail Media Networks

LDSK and BlueZoo Partner to Deliver Unprecedented Accuracy and Audience Targeting for DOOH and Retail Media Networks

By combining BlueZoo's audience measurement with LDSK's intelligent scheduling, media owners can now offer the level of

March 17, 2026

Julien Dubuque International Film Festival Expands to Eight Days in 2026

Julien Dubuque International Film Festival Expands to Eight Days in 2026

The expanded eight day festival brings global filmmakers, screenings, panels, workshops, and industry events to Dubuque

March 17, 2026

Fund That Tiger Announces $1 Million Initial Close, Triggering First Capital Call for Clemson Alumni Venture Fund

Fund That Tiger Announces $1 Million Initial Close, Triggering First Capital Call for Clemson Alumni Venture Fund

Inaugural close unlocks fund's ability to make its first investments in Tiger-led startups CLEMSON, SC, UNITED STATES,

March 17, 2026

Navigating the Storm: Why Homeowners Should Prioritize Their Roof from the Experts at RoofVantage in Wilmington, NC

Navigating the Storm: Why Homeowners Should Prioritize Their Roof from the Experts at RoofVantage in Wilmington, NC

Knowing the warning signs of a possible roof failure can help homeowners make informed decisions, particularly in

March 17, 2026

HealthWorks Family Chiropractic Hosts Free Women’s Hormone Workshop in Plano on March 26th

HealthWorks Family Chiropractic Hosts Free Women’s Hormone Workshop in Plano on March 26th

Dr. Jennifer Taylor Leads “The Second Act” — a Free, One-Hour In-House Workshop for Women Navigating Hormonal Changes

March 17, 2026

Thrive Technologies Receives U.S. Patent Approval for Thermostock® AI Inventory Optimization Solution

Thrive Technologies Receives U.S. Patent Approval for Thermostock® AI Inventory Optimization Solution

We’re extremely proud of the proprietary science behind Thermostock AI, with Thrive customers experiencing dramatic

March 17, 2026

Chris Anton of Synergy Logistics Named a 2026 Supply & Demand Chain Executive Pro to Know

Chris Anton of Synergy Logistics Named a 2026 Supply & Demand Chain Executive Pro to Know

Synergy Logistics’ Chris Anton named a 2026 “Pro to Know” by Supply & Demand Chain Executive for driving supply

March 17, 2026

MediaMint Appoints Krishan Bhatia as Board Advisor to Support Next Phase of Company Growth

MediaMint Appoints Krishan Bhatia as Board Advisor to Support Next Phase of Company Growth

Krishan brings leadership experience from Amazon and NBCUniversal to advise on strategic growth, partnerships, and

March 17, 2026

Birdeye Sweeps G2 Rankings: Named a Top Global Software Company and AI Leader

Birdeye Sweeps G2 Rankings: Named a Top Global Software Company and AI Leader

#1 Enterprise Leader across 10+ categories, fueled by a 113% surge in enterprise adoption. Earning a Leader position in

March 17, 2026

Powers Parts Announces Exclusive Distribution Deal with Cummins & Phoenix EV for ZX5 Electric Bus Components

Powers Parts Announces Exclusive Distribution Deal with Cummins & Phoenix EV for ZX5 Electric Bus Components

DuoPower Axle and Gearbox Components Now Available Exclusively Through Powers Parts This partnership with Cummins

March 17, 2026

Insero Advisors announces membership with Aprio Alliance

Insero Advisors announces membership with Aprio Alliance

Insero Advisors will have access to global resources through Aprio Alliance while maintaining its independence and

March 17, 2026

FunnL Surpasses 450 Clients as Human-Led AI Drives Demand for Real B2B Sales Meetings

FunnL Surpasses 450 Clients as Human-Led AI Drives Demand for Real B2B Sales Meetings

As AI outreach fatigue grows, demand for qualified sales meetings is reshaping how B2B pipeline gets built PA, UNITED

March 17, 2026

Children of the Magenta Line: What 150,000 Safety Records Reveal About the Next Generation of Pilots

Children of the Magenta Line: What 150,000 Safety Records Reveal About the Next Generation of Pilots

The cockpit technology designed to make flying safer is producing pilots who cannot fly without it — and federal safety

March 17, 2026

RUiXU and EVONOMY Energy Announce Strategic Partnership to Accelerate Lithium Energy Storage Adoption in the U.S.

RUiXU and EVONOMY Energy Announce Strategic Partnership to Accelerate Lithium Energy Storage Adoption in the U.S.

EVONOMY’s capabilities in product sales and system engineering complement RUiXU’s mission to deliver high-performance

March 17, 2026

Go2Africa Releases its 2025 Annual State of Safari Report

Go2Africa Releases its 2025 Annual State of Safari Report

A Look Back on the Year’s Shift Toward Regenerative Luxury, Shoulder Season Travel, and Intentional Exploration If you

March 17, 2026

Lumea and elea Launch A Unified Pathology Ecosystem, Merging Best-in-Class IMS with AI-Native LIS

Lumea and elea Launch A Unified Pathology Ecosystem, Merging Best-in-Class IMS with AI-Native LIS

elea selects Lumea as its preferred digital pathology partner for its launch into the U.S. market. LEHI, UT, UNITED

March 17, 2026

COPILOT Provider Services Rebrands as Elusa Health, Launching New Identity Built on Clarity and Access

COPILOT Provider Services Rebrands as Elusa Health, Launching New Identity Built on Clarity and Access

The company's rebrand as Elusa Health marks a significant evolution in in its commitment to transforming how patients

March 17, 2026

Influential Women Spotlights Eva M. O’Keefe, MBA: Strategic Leader and Growth Driver in Specialty Chemicals

Influential Women Spotlights Eva M. O’Keefe, MBA: Strategic Leader and Growth Driver in Specialty Chemicals

LOS ANGELES, CA, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Senior Vice President at Azelis Translates Market

March 17, 2026

Printful Reveals 2026 Trends in Marketing to Gen Alpha

Printful Reveals 2026 Trends in Marketing to Gen Alpha

Early brand interaction—not purchasing power—is what will determine long-term loyalty Marketing to Gen Alpha isn’t

March 17, 2026

Sunstone Digital Tech Drives Customer Engagement With Strategic Email Marketing Services

Sunstone Digital Tech Drives Customer Engagement With Strategic Email Marketing Services

Sunstone Digital Tech enhances its digital marketing portfolio by delivering data-driven email marketing services

March 17, 2026

Printful Releases the Ultimate Quality Guide to the Best Blank Hoodies for Printing in 2026

Printful Releases the Ultimate Quality Guide to the Best Blank Hoodies for Printing in 2026

Why fabric, fit, and print compatibility—not price—will define long-term ecommerce success For experienced sellers, the

March 17, 2026

Cynthia Encinas-Concordia, Recognized By Influential Women, Transformational Life Coach, Speaker, and Author

Cynthia Encinas-Concordia, Recognized By Influential Women, Transformational Life Coach, Speaker, and Author

FAIRFAX, VA, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Founder and CEO of Dream to Rise LLC, Empowering

March 17, 2026

EnviroPro 360 Expands Asbestos Inspection Capacity Amid Regional Shortage of Certified Inspectors

EnviroPro 360 Expands Asbestos Inspection Capacity Amid Regional Shortage of Certified Inspectors

EnviroPro 360 adds EPA AHERA-certified inspector, expanding asbestos testing capacity for projects across Georgia and

March 17, 2026

Brian Bartes’ TEDx Talk, ‘What No One Tells You About Excellence’, Selected as Editor’s Pick by TED on YouTube

Brian Bartes’ TEDx Talk, ‘What No One Tells You About Excellence’, Selected as Editor’s Pick by TED on YouTube

Bartes explores the hidden truth behind greatness, showing how the extraordinary moments we celebrate are built through

March 17, 2026

Digiarty Unveils Winxvideo AI V4.8: Optimized Downloader with Multi-Language Detection and Enhanced OS Stability

Digiarty Unveils Winxvideo AI V4.8: Optimized Downloader with Multi-Language Detection and Enhanced OS Stability

Digiarty has rolled out Winxvideo AI V4.8. This version focuses on 2 key points: granular language control for

March 17, 2026

Nickole Diaz Selected to Serve on the Arkansas Financial Educators Council’s Expert Advisory Board

Nickole Diaz Selected to Serve on the Arkansas Financial Educators Council’s Expert Advisory Board

Leaders, like Nickole Diaz, who combine real-world experience and a heart for service are exactly what financial

March 17, 2026

Americase to Exhibit Lithium-Ion Battery Safety & Compliance Solutions at International Battery Seminar & Exhibit 2026

Americase to Exhibit Lithium-Ion Battery Safety & Compliance Solutions at International Battery Seminar & Exhibit 2026

Industry leader to showcase the latest protective solutions for safe and compliant battery transport and storage The

March 17, 2026

AI-Powered Enterprise GPS Fleet Tracking Platform Expands Across Dallas–Fort Worth

AI-Powered Enterprise GPS Fleet Tracking Platform Expands Across Dallas–Fort Worth

NLMJ Technologies LLC, operating as ETA Track Plus, has announced the availability of its AI-powered enterprise GPS

March 17, 2026

Influential Women Showcases Alysia Straw, MBA, SHRM-CP, aPHR: Championing Healthcare Education and Workforce Development

Influential Women Showcases Alysia Straw, MBA, SHRM-CP, aPHR: Championing Healthcare Education and Workforce Development

SPRINGFIELD, VT, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Inspiring Students and Strengthening Vermont’s

March 17, 2026

The Philippines aims to be a destination for high-value tropical flavors

The Philippines aims to be a destination for high-value tropical flavors

The Philippines aims to deliver innovative sourcing solutions to the global food stage MANILA, METRO MANILA,

March 17, 2026