ClawHub Malware Skill Detector
341+ Infected Packages Identified
Examples: crypto-wallet, email-triage-v2, file-organizer-pro
What is ClawHub Skill Malware?
ClawHub is the official skill marketplace for OpenClaw AI agents. Security researchers have identified 341+ skills containing malicious payloads as of February 2026.
Malicious skills appear legitimate but execute hidden code: data exfiltration, credential theft, remote code execution, cryptocurrency mining, and C2 beaconing.
This educational scanner uses 12 regex-based malware signature patterns matching known attack vectors plus 127 known malicious hash signatures.
Detection categories: data exfiltration, RCE, credential theft, C2 beaconing, obfuscation, persistence, crypto mining, keylogging, DNS tunneling, privilege escalation, supply chain injection, and API key harvesting.
12 Malware Signatures We Detect
curl/wget sending data to external servers
os.system/exec/eval running arbitrary commands
base64 decode + password/env harvesting
Socket/HTTP connections to command servers
Hex encoding and compile/exec chains
Crontab/bashrc/startup modifications
XMRig/Monero/CoinHive mining payloads
pynput/keyboard hooks recording input
Data exfiltration via DNS queries
sudo/chmod 777/setuid exploitation
setup.py install hooks with __import__
OPENAI/AWS/STRIPE key theft from .env
Frequently Asked Questions
OpenClaw Security Resources
OpenClaw Exposure Scanner
Scan for port 18789 exposure, CVE-2026-25253 RCE, and 7 vulnerability dimensions.
Quantum Breach Forecaster
82% of consumer data vulnerable by Q-Day 2027. Build your quantum-proof fortress.
Voice Biometric Fraud Detector
$3.2B in voice fraud losses. 82% of voices are AI-cloneable. Build your shield.
Synthetic ID Scanner
Detect synthetic identity fraud patterns before they destroy your credit.