This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

EnforceAuth Delivers Coverage of Gartner AI TRiSM Framework, Closing the Authorization Gap

EnforceAuth Delivers Coverage of Gartner AI TRiSM Framework, Closing the Authorization Gap

AI Security Fabric platform becomes the first solution purpose-built to enforce all four layers of the Gartner AI TRiSM

March 18, 2026

AIHCP Introduces Groundbreaking Certification Program in Behavioral Holistic Health Care

AIHCP Introduces Groundbreaking Certification Program in Behavioral Holistic Health Care

New Certification Program in Behavioral Holistic Health Care This certification not only enhances your expertise but

March 18, 2026

Lightspeed Systems Expands Windows on ARM Support Across Its Product Portfolio

Lightspeed Systems Expands Windows on ARM Support Across Its Product Portfolio

Lightspeed Systems® today announced expanded support for Windows on ARM devices across its core product portfolio. By

March 18, 2026

CORRECTION Catalyst & STREAMWIDE announce collaboration to bring advanced communications capabilities to LTE Customers

CORRECTION Catalyst & STREAMWIDE announce collaboration to bring advanced communications capabilities to LTE Customers

CORRECTION FROM SOURCE: Catalyst & STREAMWIDE announce collaboration to bring advanced communications capabilities

March 18, 2026

CD Top Shelf Launches at Ann Arbor Ice Arena as a Premier Gathering Place for Ann Arbor Community

CD Top Shelf Launches at Ann Arbor Ice Arena as a Premier Gathering Place for Ann Arbor Community

BUILT on family, POWERED by community We are incredibly grateful for the opportunity to serve the Ann Arbor community,

March 18, 2026

Dr. Craig Deligdish, MD & CEO of Omni Healthcare, stresses annual health screenings to prevent long-term complications

Dr. Craig Deligdish, MD & CEO of Omni Healthcare, stresses annual health screenings to prevent long-term complications

MELBOURNE, FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Dr. Craig Deligdish, M.D. and CEO of Omni Healthcare

March 18, 2026

Pasadena Nonprofit Helps Hundreds of High School Seniors Attend Prom Through Annual Dress and Suit Giveaway

Pasadena Nonprofit Helps Hundreds of High School Seniors Attend Prom Through Annual Dress and Suit Giveaway

Fifth Annual Jazzy Jam Glam Event Returns March 28–29 at The Paseo Serving More Than 900 Families This initiative is

March 18, 2026

Routed To Heaven Ignites Global Conversation On Near-Death Experiences And Purpose-Driven Faith

Routed To Heaven Ignites Global Conversation On Near-Death Experiences And Purpose-Driven Faith

Julie Bonn Blank and fellow contributors deliver powerful testimonies of Heaven, offering hope, healing, and a renewed

March 18, 2026

Chemical Industry Veteran Launches St. Louis–Based Suppliers Chemical Serving Midwest Manufacturers

Chemical Industry Veteran Launches St. Louis–Based Suppliers Chemical Serving Midwest Manufacturers

New company provides industrial cleaning chemicals and customized supply solutions for warehouses, fleets, food

March 18, 2026

SHERATON BALTIMORE NORTH APPOINTS SETH YECINA AS GENERAL MANAGER

SHERATON BALTIMORE NORTH APPOINTS SETH YECINA AS GENERAL MANAGER

TOWSON, MD, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Sheraton Baltimore North is pleased to announce the

March 18, 2026

Capital City Classic 10K Announces Largest Prize Purse to Top 5 Male and Female Winners

Capital City Classic 10K Announces Largest Prize Purse to Top 5 Male and Female Winners

The top 5 male and female finishers of the 2026 Capital City Classic 10k will receive $1,500, $1,000, $500, $350 and

March 18, 2026

Perdata.ai sponsoring American Cancer Society’s Making Strides Against Breast Cancer walk in Washington DC

Perdata.ai sponsoring American Cancer Society’s Making Strides Against Breast Cancer walk in Washington DC

Perdata.ai, creator of www.getconexus.com will sponsor the October Making Strides against Breast Cancer walk in DC.

March 18, 2026

University Study Shows How Teens React to Influencers’ Retouched Photos in Social Media

University Study Shows How Teens React to Influencers’ Retouched Photos in Social Media

A recent study shows that, although warning labels don’t always help them spot the retouching, the mere suspicion of

March 18, 2026

The Duravent Group, Venting and Air Quality Solutions Leader, Secures Strategic Growth Investment from Bain Capital

The Duravent Group, Venting and Air Quality Solutions Leader, Secures Strategic Growth Investment from Bain Capital

Investment to accelerate Company’s growth and further scale its industry-leading platform DETROIT, MI, UNITED STATES,

March 18, 2026

Bay Atlantic Symphony’s ‘Extraordinary Contrasts’ Concert Celebrates Hope and Passion

Bay Atlantic Symphony’s ‘Extraordinary Contrasts’ Concert Celebrates Hope and Passion

Liliana Ruiz brings Flamenco to the Stage It’s some of the most magical and intimate musical expression you’ll ever

March 18, 2026

Sports Talk Florida Exclusive: HearUSA’s Dr. Jorge Rey Urges Fans to Protect Their Hearing at NCAA Tournament Games

Sports Talk Florida Exclusive: HearUSA’s Dr. Jorge Rey Urges Fans to Protect Their Hearing at NCAA Tournament Games

Dr. Jorge Rey of HearUSA spoke about protecting your hearing at events like NCAA Tournament I advocate for

March 18, 2026

FMLS Expands Global MLS Network to Enhance Real Estate Market Data Sharing and Collaboration

FMLS Expands Global MLS Network to Enhance Real Estate Market Data Sharing and Collaboration

Home buyers and sellers are looking beyond local borders—across states, countries, and even internationally. When

March 18, 2026

Five-Time Best Hair Salon in Louisville Launches Hair Emergency Protocol Guide

Five-Time Best Hair Salon in Louisville Launches Hair Emergency Protocol Guide

TRIM NuLu, five-time Best Hair Salon in Louisville, publishes a step-by-step resource for handling hair disasters in

March 18, 2026

Mirasys Appoints Steve Johnson as Computer Vision Manager to Strengthen the Dell Partnership

Mirasys Appoints Steve Johnson as Computer Vision Manager to Strengthen the Dell Partnership

Mirasys Appoints Steve Johnson as Computer Vision Manager to Strengthen Dell Partnership and Deliver White-Glove

March 18, 2026

C-BATT™ to Present New Obsidia™ Anode Results at International Battery Seminar & Exhibit

C-BATT™ to Present New Obsidia™ Anode Results at International Battery Seminar & Exhibit

Testing highlights new performance features that may enable longer battery life, deeper discharge, and improved

March 18, 2026

Revive Design and Renovation Wins Six First-Place NARI Remodeler of the Year Awards

Revive Design and Renovation Wins Six First-Place NARI Remodeler of the Year Awards

The awards recognize the very best the remodeling industry has to offer across all phases of residential design and

March 18, 2026

INSIGNIA INTERNATIONAL LAUNCHES FIVE NEW PRODUCTS AS CONSUMER TASTES EVOLVE

INSIGNIA INTERNATIONAL LAUNCHES FIVE NEW PRODUCTS AS CONSUMER TASTES EVOLVE

Insignia International debuts new 505 Southwestern® and La Tortilla Factory® products, focusing on fruit-forward,

March 18, 2026

R.M. Almonte Continues 50-State Book Tour with 49 States Completed and Wisconsin Remaining

R.M. Almonte Continues 50-State Book Tour with 49 States Completed and Wisconsin Remaining

R.M. Almonte Continues 50-State Book Tour with 49 States Completed and Wisconsin Remaining MILWAUKEE, WI, UNITED

March 18, 2026

San Diego BMW Motorcycles Invites All Riders to Scenic Sunrise Highway Group Ride on March 21

San Diego BMW Motorcycles Invites All Riders to Scenic Sunrise Highway Group Ride on March 21

Join riders of all brands for a stunning Sunrise Highway adventure: pine forests, desert views, Mount Laguna, and Lake

March 18, 2026

Lagos-Born Artist Chinedu Victor Opens Solo Exhibition ‘Memories of an Undocumented Past’ in New York

Lagos-Born Artist Chinedu Victor Opens Solo Exhibition ‘Memories of an Undocumented Past’ in New York

DFN Projects is pleased to present Memories of an Undocumented Past, the debut solo exhibition by Chinedu Victor,

March 18, 2026

Groundbreaking AI-Generated Documentary on Science and Faith Premieres April 8

Groundbreaking AI-Generated Documentary on Science and Faith Premieres April 8

In an era of high anxiety about artificial intelligence, one former Harvard physicist is using it to explore God.

March 18, 2026

Intelligent Diva Shatters Industry Norms with Human-AI Hybrid Single ‘Nobody Like You’ & Enterprise-Grade Tech Ecosystem

Intelligent Diva Shatters Industry Norms with Human-AI Hybrid Single ‘Nobody Like You’ & Enterprise-Grade Tech Ecosystem

FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — High-tech visionary and recording artist Intelligent Diva

March 18, 2026

VegasAilure.com Launches ‘Agent Ailure’: The First Agentic AI Travel Architect for the Las Vegas Strip

VegasAilure.com Launches ‘Agent Ailure’: The First Agentic AI Travel Architect for the Las Vegas Strip

New custom GPT and workspace platform turn ChatGPT trip planning into system-verified Las Vegas itineraries and

March 18, 2026

Paramount Roofing Announces Plymouth, MI Expansion with Official Ribbon Cutting Ceremony

Paramount Roofing Announces Plymouth, MI Expansion with Official Ribbon Cutting Ceremony

New location at 963 W Ann Arbor Trail strengthens service across Metro Detroit with faster inspections, estimates, and

March 18, 2026

Epic Authenticity, Permission Granted Speaking Tour from the Creator of Women for Women Today

Epic Authenticity, Permission Granted Speaking Tour from the Creator of Women for Women Today

WESTWOOD, NJ, UNITED STATES, March 18, 2026 /EINPresswire.com/ — T.H. Irwin, MBA, a veteran experiential creator and

March 18, 2026

ANNE SCHAEDDEL SELECTED FOR TOP 50 FEARLESS LEADERS BY IAOTP

ANNE SCHAEDDEL SELECTED FOR TOP 50 FEARLESS LEADERS BY IAOTP

The International Association of Top Professionals (IAOTP) will honor Anne Schaeddel at their annual awards gala in NYC

March 18, 2026

Currie Green Announces Expansion With New Building for Enhanced and Memory Care

Currie Green Announces Expansion With New Building for Enhanced and Memory Care

Currie Green expands its Calgary senior living campus with a new building for enhanced and memory care, supporting

March 18, 2026

Industry-Led Geofencing Project Kicks Off Support for Next Generation 6 GHz Unlicensed Devices

Industry-Led Geofencing Project Kicks Off Support for Next Generation 6 GHz Unlicensed Devices

WInnForum launches a new effort to define and test Geofenced Variable Power (GVP) device capabilities and incumbent

March 18, 2026

Halemont Capital Expands Strategic Capital Advisory Support for Founders Preparing for Meaningful Raises

Halemont Capital Expands Strategic Capital Advisory Support for Founders Preparing for Meaningful Raises

Halemont Capital helps founders strengthen investor positioning, capital structure, and negotiation readiness before

March 18, 2026

The Invisible Everywhere: Scientist Explains Why Modern Physics Points to God in New Documentary

The Invisible Everywhere: Scientist Explains Why Modern Physics Points to God in New Documentary

Dr. Michael Guillén says his deep understanding of science — including modern cosmology and human consciousness —

March 18, 2026

DreamCollege.ai Launches School Edition to Scale Personalized College Admissions Guidance

DreamCollege.ai Launches School Edition to Scale Personalized College Admissions Guidance

New Human + AI platform helps schools expand personalized college admissions guidance, increase counselor capacity, and

March 18, 2026

Michigan Entrepreneurs to Converge in Southfield for High-Stakes Pitch Competition and Business Expo

Michigan Entrepreneurs to Converge in Southfield for High-Stakes Pitch Competition and Business Expo

Pitch competitions are a powerful catalyst for innovation, giving entrepreneurs a platform to showcase their ideas and

March 18, 2026

Historic Petaluma Landmark ‘Hall of the Above’ Celebrates 100 Years with Centennial Party on April 25

Historic Petaluma Landmark ‘Hall of the Above’ Celebrates 100 Years with Centennial Party on April 25

Hall of the Above marks 100 years since the building first opened to the public with a special centennial celebration

March 18, 2026

Legendary Fire Instructors Converge in Colorado Springs Focused on Interior Attacks in High-Rise and Big-Box Fires

Legendary Fire Instructors Converge in Colorado Springs Focused on Interior Attacks in High-Rise and Big-Box Fires

Fire in the Sky 2026 Unites Veterans from FDNY, Chicago, Seattle, Denver and Beyond for Three Days of High-Rise and

March 18, 2026

Jason Ruedy Says Fort Collins Investors Are Turning to DSCR Loans for Rental Properties

Jason Ruedy Says Fort Collins Investors Are Turning to DSCR Loans for Rental Properties

Fort Collins Mortgage Expert Jason Ruedy “The Home Loan Arranger” Says DSCR Loans Are Helping Real Estate Investors

March 18, 2026