This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Aedan Looking Glass Inc. Signs Agreement for 200MW Data Center Project in South Korea

Aedan Looking Glass Inc. Signs Agreement for 200MW Data Center Project in South Korea

Aedan Looking Glass Inc. Signs Agreement for 200MW Data Center Project in South Korea Turnkey Capital Inc

March 22, 2026

Innovative Concrete Solutions Launches Custom Pool & Spa Services, Bringing Resort-Style Backyards to Oregon Homeowners

Innovative Concrete Solutions Launches Custom Pool & Spa Services, Bringing Resort-Style Backyards to Oregon Homeowners

EUGENE, OR, UNITED STATES, March 22, 2026 /EINPresswire.com/ — Innovative Concrete Solutions, a leading concrete

March 22, 2026

Kempf Construction LLC Expands Service Across the Willamette Valley, Strengthening Its Commitment to Quality Builds

Kempf Construction LLC Expands Service Across the Willamette Valley, Strengthening Its Commitment to Quality Builds

As a licensed general contractor in Eugene, Oregon, we proudly serve clients throughout the Willamette Valley with

March 22, 2026

Charge Home Solutions: the Top Home Services Startup to Watch in 2026

Charge Home Solutions: the Top Home Services Startup to Watch in 2026

Tesla-certified platform dubbed the "Uber of Electricians" targets $1B valuation amid historic electrician shortage LAS

March 22, 2026

IMPERIUM Enters a New Phase of Development Following Patent Protection for Its Revolving Export-Backed Digital Currency

IMPERIUM Enters a New Phase of Development Following Patent Protection for Its Revolving Export-Backed Digital Currency

Perpetual Export Smart Contracts Create a Digital Currency Designed for Endurance, Scale, and Economic Stability

March 22, 2026

Pittsburgh Symphony Orchestra to Welcome NFL Draft Visitors via Holograms at Pittsburgh International Airport

Pittsburgh Symphony Orchestra to Welcome NFL Draft Visitors via Holograms at Pittsburgh International Airport

Around-the-clock performances presented using cutting-edge holograms intended to show hundreds of thousands of visitors

March 22, 2026

WattBase Launches Platform to Help E-Bike Fleets Reduce Downtime and Improve Operations

WattBase Launches Platform to Help E-Bike Fleets Reduce Downtime and Improve Operations

New platform gives e-bike fleet operators real-time diagnostics, maintenance tracking, and operational visibility.

March 22, 2026

Ewa Moving Co. Strengthens Its Presence as a Trusted Moving Company in Honolulu, HI

Ewa Moving Co. Strengthens Its Presence as a Trusted Moving Company in Honolulu, HI

Locally owned mover strengthens island-wide services with a focus on reliability, transparency, and community-first

March 22, 2026

Albuquerque’s Top Moving Company, JP Moving, Partners with Local Businesses to Offer Discounted Moving Services

Albuquerque’s Top Moving Company, JP Moving, Partners with Local Businesses to Offer Discounted Moving Services

Leading Albuquerque moving company launches collaborative discount program for residential and commercial customers.

March 22, 2026

Herb + Ōhm Brings Advanced Orthopedic Acupuncture to Chicago as Spring Demand for Dry Needling Surges

Herb + Ōhm Brings Advanced Orthopedic Acupuncture to Chicago as Spring Demand for Dry Needling Surges

Downtown Chicago’s premier integrative medicine clinic offers a clinically superior alternative to standalone dry

March 22, 2026

Next Step Filings Reports 93% Client Satisfaction Across 20,000 Business Filings

Next Step Filings Reports 93% Client Satisfaction Across 20,000 Business Filings

Virginia-based compliance firm achieves 93% client satisfaction and 90% return rate across 20,000 filings in 12 states.

March 22, 2026

CATCH BLAKE RIDDER’S HELP: THE AWARD-WINNING THRILLER

CATCH BLAKE RIDDER’S HELP: THE AWARD-WINNING THRILLER

A seductive, slow-burn nightmare — now streaming free. I wanted to explore how quickly trust can erode when the truth

March 22, 2026

The Donny & Marie Osmond Children’s Song Collection – supports children who struggle with reading.

The Donny & Marie Osmond Children’s Song Collection – supports children who struggle with reading.

This 25-song collection is designed for first- and second-grade learners, with each song targeting an essential reading

March 22, 2026

FOX UNVEILS EXCLUSIVE MINNIE DRIVER SPECIAL TEASER FOR ‘THE FAITHFUL: WOMEN OF THE BIBLE’ AHEAD OF SUNDAY PREMIERE

FOX UNVEILS EXCLUSIVE MINNIE DRIVER SPECIAL TEASER FOR ‘THE FAITHFUL: WOMEN OF THE BIBLE’ AHEAD OF SUNDAY PREMIERE

The Biblical series debuts March 22 on FOX as a three-week television event, culminating Easter Sunday NASHVILLE, TN,

March 22, 2026

Charge Rigs Unveils the First End-to-End Design and Quoting Platform Built Exclusively for EV Charging Contractors

Charge Rigs Unveils the First End-to-End Design and Quoting Platform Built Exclusively for EV Charging Contractors

Install Planner replaces fragmented CAD, spreadsheet, and email workflows with a single intelligent system – from

March 22, 2026

Absolute Sign Solutions Confirm Growing Demand In Sydney For Custom Made Honour Boards

Absolute Sign Solutions Confirm Growing Demand In Sydney For Custom Made Honour Boards

In an exclusive interview with Metro Cities Media, Absolute Sign Solutions confirmed the growing trend for custom made

March 22, 2026

A Thousand‑Year Silence Ends: C.S. Douglas Revives the Ancient Art of the Rubáiyát in Quatrains: Echoes of Existence

A Thousand‑Year Silence Ends: C.S. Douglas Revives the Ancient Art of the Rubáiyát in Quatrains: Echoes of Existence

A Contemporary Contribution to the Eternal Library of Human Thought Past and Future meet inside Awareness, while the

March 22, 2026

The People’s Chamber of Commerce Releases Free AI Tool for Press Interviews, Company Branding and Media Positioning

The People’s Chamber of Commerce Releases Free AI Tool for Press Interviews, Company Branding and Media Positioning

Free AI tool from The People’s Chamber of Commerce helps entrepreneurs secure media exposure, build authority, and turn

March 22, 2026

Rev. Dr. Michael Bernard Beckwith Joins the Cast of ‘Pillars of Power: The Hidden Secret Behind Achieving Greatness’

Rev. Dr. Michael Bernard Beckwith Joins the Cast of ‘Pillars of Power: The Hidden Secret Behind Achieving Greatness’

Founder of Agape International Spiritual Center Joins Original Stars of The Secret in Landmark Documentary on Its 20th

March 22, 2026

Alien Adversary Reveals a Chilling Encounter With Forces Beyond Human Understanding

Alien Adversary Reveals a Chilling Encounter With Forces Beyond Human Understanding

A provocative sci-fi thriller that challenges truths, explores hidden realities, and pushes readers to question belief

March 22, 2026

The Veteran Explores Identity, Marriage, and the Quiet Struggles of Modern Life

The Veteran Explores Identity, Marriage, and the Quiet Struggles of Modern Life

In The Veteran, Clarke Owens delivers a psychologically rich novel examining relationships, mortality, and the search

March 22, 2026

Malatya Apricot | Dried Apricots , Dried Figs , Dried Tomatoes Delivery Worldwide with Quality, Reliability

Malatya Apricot | Dried Apricots , Dried Figs , Dried Tomatoes Delivery Worldwide with Quality, Reliability

Malatya apricots have long been synonymous with superior taste, texture, and nutritional value. Grown under ideal

March 22, 2026

Cheer Athletics Telford Earns Standing Ovation on Britain’s Got Talent

Cheer Athletics Telford Earns Standing Ovation on Britain’s Got Talent

Cheer Athletics Telford earns standing ovation on Britain’s Got Talent with standout Dance Athletics Pom team

March 21, 2026

“Croatian Travel Blogger Helps American and British Tourists Plan the Perfect Trip to Croatia”

“Croatian Travel Blogger Helps American and British Tourists Plan the Perfect Trip to Croatia”

Founder of KarlaTypes.com reaches more than 600,000 annual views with her in-depth Croatia travel guides and

March 21, 2026

Sober On Demand Expands Into Adolescent Mental Health, Intervention, and Full-Service Case Management

Sober On Demand Expands Into Adolescent Mental Health, Intervention, and Full-Service Case Management

Sober On Demand expands into adolescent mental health, intervention, sober companions, and case management, offering

March 21, 2026

AdvocateIQ Launches New Platform to Help Texas Parents Navigate Special Education

AdvocateIQ Launches New Platform to Help Texas Parents Navigate Special Education

Texas-based startup turns a decade of advocacy expertise into affordable, automated IEP and 504 Plan support for

March 21, 2026

Doping Technology Debuts Two Global EdTech Platforms at the World’s Premier Education Summit

Doping Technology Debuts Two Global EdTech Platforms at the World’s Premier Education Summit

"A Turkish Company at the Champions League of Education" At the ASU+GSV Summit — attended by more than 7,000 global

March 21, 2026

Tip Top Roofing Service Expands Statewide Digital Presence With Comprehensive Arizona Roofing Resource Hub for 39 Cities

Tip Top Roofing Service Expands Statewide Digital Presence With Comprehensive Arizona Roofing Resource Hub for 39 Cities

Scottsdale's BBB-Accredited, GAF-Certified roofer now covers 39 Arizona cities. Roof repair, replacement, inspection

March 21, 2026

New to The Street Announces Broadcast of Show #739 on Bloomberg Television Across the U.S. at 6:30 PM EST

New to The Street Announces Broadcast of Show #739 on Bloomberg Television Across the U.S. at 6:30 PM EST

Featured Companies Include FreeCast (NASDAQ:CAST), KLED.ai, Lantern Pharma (NASDAQ:LTRN), and BlackBarn Restaurant NEW

March 21, 2026

Ageless Living Manhattan Magazine Features Kelly Killoren Bensimon in Spring 2026 Issue

Ageless Living Manhattan Magazine Features Kelly Killoren Bensimon in Spring 2026 Issue

The Spring 2026 issue of Ageless Living Manhattan features Kelly Killoren Bensimon on reinvention, modern

March 21, 2026

Ageless Living LA Magazine Unveils Spring Cover Featuring Marion Jones and a New Vision of Strength

Ageless Living LA Magazine Unveils Spring Cover Featuring Marion Jones and a New Vision of Strength

In an exclusive feature, Marion Jones reflects on resilience, reinvention, and how purpose and wellness now define her

March 21, 2026

SMX Redefines Trust, Provenance, and Transparency in the Global Luxury Market

SMX Redefines Trust, Provenance, and Transparency in the Global Luxury Market

NEW YORK CITY, NY / ACCESS Newswire / March 21, 2026 / SMX (Security Matters) PLC (NASDAQ:SMX) is reshaping the

March 21, 2026

SMX Reinforces Trust, Traceability, and Market Value Across Rare Earths and Precious Metals

SMX Reinforces Trust, Traceability, and Market Value Across Rare Earths and Precious Metals

NEW YORK CITY, NY / ACCESS Newswire / March 21, 2026 / SMX (Security Matters) PLC (NASDAQ:SMX) is redefining how rare

March 21, 2026

Routed To Heaven Ignites Global Conversation On Near-Death Experiences And Purpose-Driven Faith

Routed To Heaven Ignites Global Conversation On Near-Death Experiences And Purpose-Driven Faith

Julie Bonn Blank and fellow contributors deliver powerful testimonies of Heaven, offering hope, healing, and a renewed

March 21, 2026

BYAHT Inc. Pioneers Feedback-Driven AI Agent System to Revolutionize Influencer Marketing ROI

BYAHT Inc. Pioneers Feedback-Driven AI Agent System to Revolutionize Influencer Marketing ROI

Glow.B transitions to an AI agent-based architecture, bridging the gap between social media campaigns and generative AI

March 21, 2026

Valencia AI Governance Startup Deploys Open-Source Nervous System Framework

Valencia AI Governance Startup Deploys Open-Source Nervous System Framework

Former training and development professional builds AI governance framework now managing 13 autonomous agents for

March 21, 2026

Johnson & Daly Moving & Storage Ready to Welcome Richmond’s Downtown Housing Boom

Johnson & Daly Moving & Storage Ready to Welcome Richmond’s Downtown Housing Boom

As up to 900 new housing units reshape downtown Richmond, CA, Johnson & Daly Moving & Storage stands ready to

March 21, 2026

TSA Workers Nationwide Receive Free Tax Returns Through ATAX Community Initiative

TSA Workers Nationwide Receive Free Tax Returns Through ATAX Community Initiative

Local communities rally behind TSA workers through growing nationwide effort providing financial relief and

March 21, 2026

FixWell Appliance Repair Brings Honest, Fast Service to San Francisco and Marin County

FixWell Appliance Repair Brings Honest, Fast Service to San Francisco and Marin County

Locally owned and A+ BBB rated, FixWell earns 200+ five-star reviews for honest pricing and same-day repairs in the Bay

March 21, 2026

Why Homeowners Need Pre‑Storm Roof Readiness For Florida’s 2026 Rainy Season Now

Why Homeowners Need Pre‑Storm Roof Readiness For Florida’s 2026 Rainy Season Now

John Keller Roofing urges Central Florida homeowners to schedule spring roof inspections before peak storm season

March 21, 2026