This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Titan Pest Services Introduces Advanced Termite Control Solutions for Property Protection

Titan Pest Services Introduces Advanced Termite Control Solutions for Property Protection

Titan Pest Services introduces advanced termite control solutions to help protect homes and businesses with effective,

March 18, 2026

Cabinet & Counter Expo Showcases Innovative Kitchen Cabinet Refacing Solutions for Cost-Effective Remodeling

Cabinet & Counter Expo Showcases Innovative Kitchen Cabinet Refacing Solutions for Cost-Effective Remodeling

Cabinet & Counter Expo highlights innovative kitchen cabinet refacing solutions that deliver a stylish, affordable,

March 18, 2026

Energy infrastructure boom drives demand as TreadStone Technologies adds veteran tech executive Carl D. Glaeser to board

Energy infrastructure boom drives demand as TreadStone Technologies adds veteran tech executive Carl D. Glaeser to board

Palladian Capital Partners co-founder helps TreadStone scale advanced materials platform supporting hydrogen, grid

March 18, 2026

RadSite to Host Webinar on Promoting Radiology Technologist Skill Quantification: From Competency to Consistency

RadSite to Host Webinar on Promoting Radiology Technologist Skill Quantification: From Competency to Consistency

RadSite to Host Complimentary Session on March 25 As imaging technology and workflows continue to evolve, organizations

March 18, 2026

Apogee Professionals Launches to Provide Comprehensive Wealth and Life Advisory Services for Athletes and Their Families

Apogee Professionals Launches to Provide Comprehensive Wealth and Life Advisory Services for Athletes and Their Families

Former Collegiate and Professional Athletes Launch Specialized Firm Offering "Play with Heart. Rest with Confidence.”

March 18, 2026

‘Voted Best’ Garage Door Repair Pasadena Expands Rapid Fleet

‘Voted Best’ Garage Door Repair Pasadena Expands Rapid Fleet

"Voted Best garage door company Pasadena," we are expanding our rapid response fleet to provide 24/7 emergency repairs

March 18, 2026

CatalystIQ and Halpern Advisory Merge to Form Gate City Advisory

CatalystIQ and Halpern Advisory Merge to Form Gate City Advisory

Merger of equals creates a new Atlanta-based firm combining transaction advisory, CFO services, and AI-powered

March 18, 2026

Sonoma Pharmaceuticals Announces Launch of New Dermatology Product Line under Person & Covey’s Aquanil Brand for Sensitive Skin

Sonoma Pharmaceuticals Announces Launch of New Dermatology Product Line under Person & Covey’s Aquanil Brand for Sensitive Skin

BOULDER, CO / ACCESS Newswire / March 18, 2026 / Sonoma Pharmaceuticals, Inc. (Nasdaq:SNOA), a global healthcare leader

March 18, 2026

Three New Courses for Engineering CE/PDH Make Learning Purposeful and Actionable

Three New Courses for Engineering CE/PDH Make Learning Purposeful and Actionable

CE From Amber Book is Structured for How Engineers Want to Grow and Accelerate Their Careers BLACKSBURG, VA / ACCESS

March 18, 2026

FDA Feedback Supports Extension Phase for Jaguar Health’s Clinical Trial of Crofelemer for Treatment of Microvillus Inclusion Disease (MVID)

FDA Feedback Supports Extension Phase for Jaguar Health’s Clinical Trial of Crofelemer for Treatment of Microvillus Inclusion Disease (MVID)

MVID has a lethal natural history requiring life-sustaining parenteral support (PS), which includes total parenteral

March 18, 2026

Mercury CEO Josh Medow Named “Rising Star” in 2026 Pros to Know Awards by Supply & Demand Chain Executive

Mercury CEO Josh Medow Named “Rising Star” in 2026 Pros to Know Awards by Supply & Demand Chain Executive

The 2026 Pros to Know Awards recognizes outstanding executives who serve as an example for other leaders looking to

March 18, 2026

Modulate Launches Velma Transcribe: High-Performance Transcription For Real World Conversations at 90% Lower Cost

Modulate Launches Velma Transcribe: High-Performance Transcription For Real World Conversations at 90% Lower Cost

Modulate's ELM model architecture unlocks transcription for the masses, cutting costs by 10x while achieving

March 18, 2026

ZeOmega Recognized in the 2026 Gartner(R) Market Guide for Intelligent Prior Authorization, U.S. Healthcare Organizations

ZeOmega Recognized in the 2026 Gartner(R) Market Guide for Intelligent Prior Authorization, U.S. Healthcare Organizations

PLANO, TX / ACCESS Newswire / March 18, 2026 / ZeOmega, the industry's leading population health management

March 18, 2026

The City is the Farm: How Chef Aidan’s ‘Eleven98’ is Leading the Hyperlocal Revolution in East London

The City is the Farm: How Chef Aidan’s ‘Eleven98’ is Leading the Hyperlocal Revolution in East London

How Aidan’s Eleven98 and Eatwith are bursting the luxury cocoon, turning East London’s Hackney into a hyper-local farm

March 18, 2026

CloudEagle.ai Now Gives Enterprises Usage and Spend Visibility into Claude, Cursor, and Gemini

CloudEagle.ai Now Gives Enterprises Usage and Spend Visibility into Claude, Cursor, and Gemini

CloudEagle.ai tracks usage and spend for AI tools like Claude, Cursor, and Gemini, giving enterprises visibility to

March 18, 2026

RepSpark Awarded Key Placements in G2’s Spring 2026 E-Commerce Reports

RepSpark Awarded Key Placements in G2’s Spring 2026 E-Commerce Reports

Leading B2B Wholesale Platform Recognized for High Performance, Exceptional Relationship Quality, and Superior

March 18, 2026

New Geocaching Tour Launches: Historic Sadieville Geotrail ‘Legacy of the Mules’ Recalls Community’s Past

New Geocaching Tour Launches: Historic Sadieville Geotrail ‘Legacy of the Mules’ Recalls Community’s Past

Sadieville and Georgetown/Scott County Tourism launch the Historic Sadieville Geotrail: Legacy of the Mules on April

March 18, 2026

KADEN & KAI Introduces ‘Performance Jewelry’, A New Category of Jewelry Made for Movement

KADEN & KAI Introduces ‘Performance Jewelry’, A New Category of Jewelry Made for Movement

Lexington, Massachusetts designer Lisa Cassidy launches KADEN & KAI performance jewelry — bold sculptural designs

March 18, 2026

Civic Futures Institute Launches to Restore Civic Imagination

Civic Futures Institute Launches to Restore Civic Imagination

We have lost the ability – and the invitation – to imagine a better civic future.”— Dr. Lisa Duty, founder of Civic

March 18, 2026

Tom Jackobs Introduces Fractional Sales Leadership to Empower Wellness Professionals in Converting Leads

Tom Jackobs Introduces Fractional Sales Leadership to Empower Wellness Professionals in Converting Leads

AI-enhanced sales systems and structured leadership services are designed to convert leads into loyal clients. Many

March 18, 2026

TuxCare to Feature Extended Lifecycle Support for Open-Source Software at CloudFest 2026

TuxCare to Feature Extended Lifecycle Support for Open-Source Software at CloudFest 2026

PALO ALTO, CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — TuxCare, a global innovator in securing open source,

March 18, 2026

The Engagement Gap: Most Websites Lose Users After Just 56 Seconds

The Engagement Gap: Most Websites Lose Users After Just 56 Seconds

Riddle Marketing Report 2025 Reveals Interactive Formats Transform User Attention and Data Quality Interactive

March 18, 2026

Divine Kailash Announces Kailash Manasarovar Yatra 2026 by Road, Helicopter and Nepalgunj Route Pilgrimage Packages

Divine Kailash Announces Kailash Manasarovar Yatra 2026 by Road, Helicopter and Nepalgunj Route Pilgrimage Packages

Leading spiritual travel company unveils three carefully crafted pilgrimage routes for the holy Kailash Manasarovar

March 18, 2026

MMCG releases Comprehensive Multifamily Market Report as $162 Billion Loan Maturity Wall Looms Over Apartment Sector

MMCG releases Comprehensive Multifamily Market Report as $162 Billion Loan Maturity Wall Looms Over Apartment Sector

SAN FRANCISCO, CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — MMCG Invest, LLC, a commercial real estate

March 18, 2026

CoStar Group Recognizes Cravey Real Estate Services with 2025 Power Broker Awards

CoStar Group Recognizes Cravey Real Estate Services with 2025 Power Broker Awards

CORPUS CHRISTI, TX, UNITED STATES, March 18, 2026 /EINPresswire.com/ — CoStar Group (NASDAQ: CSGP), the premier

March 18, 2026

Your menu now talks back: QRCodeKIT launches AI-powered conversational QR menus for hospitality venues worldwide

Your menu now talks back: QRCodeKIT launches AI-powered conversational QR menus for hospitality venues worldwide

With a single activation, any QR menu becomes an assistant that instantly answers guest questions. If you already have

March 18, 2026

City of Decatur Introduces ‘Decatur Direct’ a New AI Chatbot Powered by Ordinal Connect

City of Decatur Introduces ‘Decatur Direct’ a New AI Chatbot Powered by Ordinal Connect

Government AI chatbot improves public access to city services while reducing the call and email load on City staff. Our

March 18, 2026

Healthcare Practices Prepare for Busy Season with Virtual Receptionist Coverage

Healthcare Practices Prepare for Busy Season with Virtual Receptionist Coverage

Industry data shows patient access challenges and workforce strain intensify during high-volume periods The busy season

March 18, 2026

Dr. Shameka Jones, of VeraRosa Higher Education Scholarship, Selected to Georgia Financial Educators Council Board

Dr. Shameka Jones, of VeraRosa Higher Education Scholarship, Selected to Georgia Financial Educators Council Board

Dr. Shameka Jones proves that financial wellness is a foundation for physical and community health.”— Vince Shorb, CEO,

March 18, 2026

SGS launches SGS Nexus – a new global food intelligence platform

SGS launches SGS Nexus – a new global food intelligence platform

New digital platform combines regulatory intelligence, food safety analytics and AI-driven risk detection With SGS

March 18, 2026

CytoNiche’s 3D FloTrix™ Platform Wins ‘Emerging Bioprocessing Supplier Award’ at ABEA 2026

CytoNiche’s 3D FloTrix™ Platform Wins ‘Emerging Bioprocessing Supplier Award’ at ABEA 2026

CytoNiche’s 3D FloTrix™ platform won the Emerging Bioprocessing Supplier – Downstream award at ABEA 2026, recognising

March 18, 2026

Aiarty Image Enhancer Advances Realism in AI Image Enhancement with High-Fidelity Results

Aiarty Image Enhancer Advances Realism in AI Image Enhancement with High-Fidelity Results

Aiarty Image Enhancer addresses concerns over the waxy AI look, delivering natural, high-fidelity image enhancement

March 18, 2026

env zero and CloudQuery Announce Merger to Create the Industry’s First Unified Cloud Intelligence Platform

env zero and CloudQuery Announce Merger to Create the Industry’s First Unified Cloud Intelligence Platform

BOSTON, MA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — env zero (envzero.com), the leader in Infrastructure as

March 18, 2026

United Planet Showcases the Future of Global Education at The Forum on Education Abroad

United Planet Showcases the Future of Global Education at The Forum on Education Abroad

United Planet highlights service-learning, global internships, and new college credit pathways at a leading global

March 18, 2026

NASHVILLE DANCE FEST RETURNS TO MUSIC CITY – SEPTEMBER 4 – 6, 2026

NASHVILLE DANCE FEST RETURNS TO MUSIC CITY – SEPTEMBER 4 – 6, 2026

Labor Day Weekend Event Boasts Eight Dance Floors, Competitive Dancing and Live Music Stages with Emerging Nashville

March 18, 2026

Ringover Launches Enhanced AI Assistant, Ask Empower 2.0

Ringover Launches Enhanced AI Assistant, Ask Empower 2.0

Unified comms platform adds to its native conversational AI capability, from individual call transcript analysis to

March 18, 2026

MedArrive Acquires Key Assets from Inbound Health to Expand Home Care Operations Platform

MedArrive Acquires Key Assets from Inbound Health to Expand Home Care Operations Platform

Acquisition expands MedArrive’s presence in home care market and adds patient navigation capabilities; health-tech

March 18, 2026

Charter Oak State College School of Education offers April Open House (via Zoom)

Charter Oak State College School of Education offers April Open House (via Zoom)

Online Undergraduate, Graduate, and Certificate Programs for Early Childhood Education Professionals NEW BRITAIN, CT,

March 18, 2026

Roquemore Skierski PLLC Expands Commercial Litigation, Real Estate Practices with Addition of Veteran Litigation Lawyers

Roquemore Skierski PLLC Expands Commercial Litigation, Real Estate Practices with Addition of Veteran Litigation Lawyers

Two highly experienced business and commercial litigation attorneys have joined the Dallas law firm Roquemore Skierski

March 18, 2026

American Academy of Pediatrics Launches New PREP Program on mon`k LMS by Impelsys

American Academy of Pediatrics Launches New PREP Program on mon`k LMS by Impelsys

Impelsys’ moǹk LMS goes live for AAP, enabling scalable, data-driven pediatric education with interactive content,

March 18, 2026