This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Institute for Education Innovation Promotes Melissa Crawl to Vice President of Membership and Strategy

Institute for Education Innovation Promotes Melissa Crawl to Vice President of Membership and Strategy

Institute for Education Innovation Promotes Melissa Crawl to Vice President of Membership and Strategy NEW YORK, NY,

March 17, 2026

GlyMed+ Celebrates 35 Years of Innovation and Unwavering Commitment to the Skincare Professional

GlyMed+ Celebrates 35 Years of Innovation and Unwavering Commitment to the Skincare Professional

GlyMed+ marks 35 years of clinical mastery, supporting 100k+ professionals with pharmaceutical-grade formulas, advanced

March 17, 2026

Cambay Solutions Unveils AI-Accelerated Engineering Blueprint in Live Webinar

Cambay Solutions Unveils AI-Accelerated Engineering Blueprint in Live Webinar

Industry leaders to share dual perspective on technical integration and human adoption, providing a roadmap to move

March 17, 2026

Superior Capital Advisors Brokers Sale of 687-Unit, 3 Property Self Storage Portfolio in Charlotte, North Carolina

Superior Capital Advisors Brokers Sale of 687-Unit, 3 Property Self Storage Portfolio in Charlotte, North Carolina

This transaction is a testament to our expertise in the self storage industry and our ability to identify and connect

March 17, 2026

New iOS App Recaid Gives Professionals a Single Tool to Capture, Transcribe, and Summarize Live Sessions

New iOS App Recaid Gives Professionals a Single Tool to Capture, Transcribe, and Summarize Live Sessions

Zurich-based productivity app consolidates audio recording, slide capture, transcription, and AI summaries into a

March 17, 2026

Melo Group Celebrates Topping Off of Downtown 6, a Mixed-Use Residential Tower in Downtown Miami

Melo Group Celebrates Topping Off of Downtown 6, a Mixed-Use Residential Tower in Downtown Miami

MIAMI, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — The Melo Group, one of South Florida’s most active and

March 17, 2026

OneVoiceFocused Launches Operational Backbone Initiative to Prevent Nonprofit Collapse in Chicagoland Neighborhoods

OneVoiceFocused Launches Operational Backbone Initiative to Prevent Nonprofit Collapse in Chicagoland Neighborhoods

Chicago-based 501(c)(3) OneVoiceFocused introduces a franchise-inspired model to strengthen governance and digital

March 17, 2026

Genuine Optics Unveils Full Portfolio of 1.6T Optical Transceivers for AI Data Center Networks

Genuine Optics Unveils Full Portfolio of 1.6T Optical Transceivers for AI Data Center Networks

Full suite of products from ACC to FRO Our 1.6T solutions are designed to help customers scale bandwidth while

March 17, 2026

BioTechnique Announces Successful DEA Licensing

BioTechnique Announces Successful DEA Licensing

New license expands BioTechnique’s capabilities in controlled‑substance manufacturing and secure pharmaceutical

March 17, 2026

Pacific Chiropractic Announces Comprehensive Auto-Accident Recovery Care

Pacific Chiropractic Announces Comprehensive Auto-Accident Recovery Care

Pacific Chiropractic & Wellness Center offers personalized, evidence-based care and integrated therapies for

March 17, 2026

DeviQA Launches Self-Healing Test Architecture to Eliminate Test Maintenance Bottlenecks

DeviQA Launches Self-Healing Test Architecture to Eliminate Test Maintenance Bottlenecks

DeviQA introduces self-healing test architecture to eliminate test maintenance bottlenecks, reduce QA effort, and

March 17, 2026

FOX5 and SSSEN Bring Las Vegas Aviators Baseball to TV Screens Across Nevada

FOX5 and SSSEN Bring Las Vegas Aviators Baseball to TV Screens Across Nevada

After a record season, select 2026 broadcasts begin with the Aviators’ first home game Bringing Aviators baseball to

March 17, 2026

SCALI RASMUSSEN FOUNDER CHRISTIAN SCALI NAMED A 2026 SOUTHERN CALIFORNIA ‘SUPER LAWYER’

SCALI RASMUSSEN FOUNDER CHRISTIAN SCALI NAMED A 2026 SOUTHERN CALIFORNIA ‘SUPER LAWYER’

LOS ANGELES, CA, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Scali Rasmussen, PC announced today that Founder

March 17, 2026

Display Week 2026 Symposium Adds Dedicated AI Track, Expands Focus on Sustainability & Automotive Research

Display Week 2026 Symposium Adds Dedicated AI Track, Expands Focus on Sustainability & Automotive Research

Peer-reviewed program reflects where global display engineering effort is concentrating this year LOS ANGELES, CA,

March 17, 2026

The Brookbush Institute Publishes a NEW Article: ‘New Research is Not Better Research’

The Brookbush Institute Publishes a NEW Article: ‘New Research is Not Better Research’

The Brookbush Institute continues to enhance education with new articles, new courses, a modern glossary, an AI Tutor,

March 17, 2026

Jenesis Software Founder Eddie Price Releases New Book to Help Independent Insurance Agencies Stand Out and Grow

Jenesis Software Founder Eddie Price Releases New Book to Help Independent Insurance Agencies Stand Out and Grow

“The Independent Insurance Agent’s Guide to Branding and Growth” offers strategies for agencies looking to build

March 17, 2026

Corva Selected as 2026 Energy Innovation Pioneer at CERAWeek

Corva Selected as 2026 Energy Innovation Pioneer at CERAWeek

Being selected for the Energy Innovation Pioneers program reflects the progress Corva is making to bring advanced

March 17, 2026

Jeff Nadrich Backs Insurance Reform as Eaton Fire Claim Delays Increase Homelessness Risk

Jeff Nadrich Backs Insurance Reform as Eaton Fire Claim Delays Increase Homelessness Risk

Attorney Jeff Nadrich backs California bills targeting insurance claim delays that are prolonging displacement for

March 17, 2026

Rewind Launches Live Podcast Studio at Shoptalk to Spotlight eCommerce Founders

Rewind Launches Live Podcast Studio at Shoptalk to Spotlight eCommerce Founders

Recorded live during the three-day event, the Back Up to Level Up Podcast will feature short interviews with founders

March 17, 2026

PanTerra Networks has earned the TrustRadius Trusted Seller Verification

PanTerra Networks has earned the TrustRadius Trusted Seller Verification

We believe buyers deserve transparency, accurate information, and a review process that is ethical and unbiased.”—

March 17, 2026

Beverly Hills Cosmetic Dentist Discusses the Transformation Behind Kylie Jenner’s Smile

Beverly Hills Cosmetic Dentist Discusses the Transformation Behind Kylie Jenner’s Smile

Beverly Hills cosmetic dentist Kevin Sands, DDS discusses the cosmetic dentistry techniques he used to create Kylie

March 17, 2026

ULTIMATE A Causation-Driven Architecture Investment System with 25-Year Track Record Offered for Institutional Licensing

ULTIMATE A Causation-Driven Architecture Investment System with 25-Year Track Record Offered for Institutional Licensing

ULTIMATE Proprietary Asset Management Algorithm NY, UNITED STATES, March 17, 2026 /EINPresswire.com/ — ULTIMATE, a new

March 17, 2026

Zion Health Introduces the Repackaged Intense Hand Repair Cream with MuruMuru Butter for Deep, Non-Greasy Moisture

Zion Health Introduces the Repackaged Intense Hand Repair Cream with MuruMuru Butter for Deep, Non-Greasy Moisture

Zion Health’s repackaged Intense Hand Repair Cream with Murumuru Butter offers a fast-absorbing formula to soothe dry,

March 17, 2026

BlueBotics bridges the gap between AGVs and AMRs with the launch of SmartPass

BlueBotics bridges the gap between AGVs and AMRs with the launch of SmartPass

The new SmartPass function meets the core efficiency goal of obstacle avoidance without the drawbacks of traditional

March 17, 2026

ACCLAIMED AUTHOR R. L. AKERS RELEASES GRIPPING NEW CRIME THRILLER GRAY DAWN ON MARCH 27

ACCLAIMED AUTHOR R. L. AKERS RELEASES GRIPPING NEW CRIME THRILLER GRAY DAWN ON MARCH 27

~Former NYPD Detective Faces Murder, Conspiracy, and Survival in the Arctic’s Endless Night~ CHARLESTON, WV, UNITED

March 17, 2026

Why Businesses Are Getting Half the Value From Their CRM Without AI Automation

Why Businesses Are Getting Half the Value From Their CRM Without AI Automation

New analysis from TFSF Ventures examines why manual CRM data entry fails businesses and how autonomous AI agents

March 17, 2026

Ambrogio, Pletter & Associates, LLC Continues Focus on Client-Centered Legal Services in Stratford, Connecticut

Ambrogio, Pletter & Associates, LLC Continues Focus on Client-Centered Legal Services in Stratford, Connecticut

Tim Pletter Emphasizes Accessible and Empathetic Support for Individuals and Small Businesses Facing Financial

March 17, 2026

Matthew Fornaro, P.A. Enhances Business Law Services with Entrepreneurial Insight in South Florida

Matthew Fornaro, P.A. Enhances Business Law Services with Entrepreneurial Insight in South Florida

Firm Combines Legal Expertise with Business Owner Perspective to Support Startups and Entrepreneurs CORAL SPRINGS, FL,

March 17, 2026

Kimberly Edington Law Firm Focuses on Client Advocacy in Arkansas Family Law

Kimberly Edington Law Firm Focuses on Client Advocacy in Arkansas Family Law

Batesville-Based Practice Offers Comprehensive Support for Domestic Relations Cases BATESVILLE, AR, UNITED STATES,

March 17, 2026

Susanne Leone of Leone Zhgun, P.A. Enhances Legal Guidance for German-Speaking Businesses in U.S. Market

Susanne Leone of Leone Zhgun, P.A. Enhances Legal Guidance for German-Speaking Businesses in U.S. Market

German-Speaking Lawyer Leverages Dual Qualification to Streamline Market Entry and Corporate Compliance for DACH Region

March 17, 2026

Simmermon Law Achieves Seven-Year 100% Patent Issuance Rate and Leads Major Infringement Lawsuit

Simmermon Law Achieves Seven-Year 100% Patent Issuance Rate and Leads Major Infringement Lawsuit

Roseville firm, led by Craig A. Simmermon, continues to provide intellectual property counsel with a record of

March 17, 2026

Jeskell Systems Named To The Prestigious CRN Tech Elite 250 For 2026

Jeskell Systems Named To The Prestigious CRN Tech Elite 250 For 2026

Jeskell is recognized for advanced expertise in delivering secure, high-performance data infrastructure solutions for

March 17, 2026

Padilla Law PLLC Founder Introduces AI Platform to Enhance Legal Service Accessibility

Padilla Law PLLC Founder Introduces AI Platform to Enhance Legal Service Accessibility

José Padilla Launches LegalMente AI to Reduce Legal Costs for Lawyers, Startups, and Businesses Globally SAN ANTONIO,

March 17, 2026

Ellis Family Law Announces Significant Growth and Expansion in North Carolina

Ellis Family Law Announces Significant Growth and Expansion in North Carolina

Firm Expands to Four Locations and Reports 200% Growth Since 2023, Reinforcing Commitment to Client Service and

March 17, 2026

Orbital Overdrive Out Now on Steam

Orbital Overdrive Out Now on Steam

Orbital Overdrive is a roguelite twin-stick shooter where your score is your currency, experience, and the price of

March 17, 2026

Valentine Roofing Wins RCAW Excellence in Roofing Award for Second Consecutive Year

Valentine Roofing Wins RCAW Excellence in Roofing Award for Second Consecutive Year

Award Recognizes Exceptional Craftsmanship on the Roof Replacement of a Historic 1889 Victorian Home in Tacoma,

March 17, 2026

Major neighborhood retail center with development potential in Agoura Hills listed for $18.1M

Major neighborhood retail center with development potential in Agoura Hills listed for $18.1M

56,259 SF Agoura Hills Town Center is nearly fully leased and located along key 101 freeway corridor. In addition to

March 17, 2026

San Diego Law Firm Weitzen Samuth Sinex & Sherry Expands Reach with Addition of Real Estate Partner, John Y. Lee

San Diego Law Firm Weitzen Samuth Sinex & Sherry Expands Reach with Addition of Real Estate Partner, John Y. Lee

Weitzen Samuth Sinex & Sherry announces John Y. Lee has joined as Partner to launch a real estate practice serving

March 17, 2026

Photoscraper.com: a website to educate everyday people about how to scrape metadata from photos

Photoscraper.com: a website to educate everyday people about how to scrape metadata from photos

Photoscraper.com helps everyday people understand photo scraping and provides them with information on how to scrape

March 17, 2026

Fieldman Introduces Fully Configurable Real-Time Project Dashboard for AMI Field Operations

Fieldman Introduces Fully Configurable Real-Time Project Dashboard for AMI Field Operations

The dashboard uses configurable charts and live operational data to help managers monitor installation progress while

March 17, 2026