OpenClaw AI Agents Hijacked to Push Malware via Malicious Skills

OpenClaw AI Agents Hijacked to Push Malware via Malicious Skills

Threat actors have begun weaponizing OpenClaw’s AI agents by publishing counterfeit “skills” that direct victims to download and execute code from untrusted URLs. VirusTotal’s recent scans flagged several of these skill packages as containing dropper payloads, turning the AI platform into an unwitting malware distribution channel.

The malicious skills can silently install ransomware, credential stealers, or backdoors on compromised machines, giving attackers footholds for further exploitation and data exfiltration. Defenders should immediately flag OpenClaw traffic, enforce strict allow‑lists for code execution, and incorporate these signatures into endpoint detection rules to stop the abuse before it spreads.

Categories: AI Security & Threats, Malware & Ransomware

Source: Read original article