This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Sodexo and Ottonomy Deploy Australia’s First Autonomous Delivery Robot at Rio Tinto Mine Village

Sodexo and Ottonomy Deploy Australia’s First Autonomous Delivery Robot at Rio Tinto Mine Village

Sodexo Australia is pioneering deliveries by autonomous robots by Ottonomy at Rio Tinto Iron Ore Gudai-Darri village,

March 18, 2026

Jobleads Study Reveals Women Enter the Job Market Expecting 9.5% Less Than Men–and the Gap Only Grows From There

Jobleads Study Reveals Women Enter the Job Market Expecting 9.5% Less Than Men–and the Gap Only Grows From There

An analysis of 881,776 U.S. job seekers shows the gender pay gap is not a single number but a pattern built across five

March 18, 2026

RedSeal Honored as Finalist of the 2026 SC Awards

RedSeal Honored as Finalist of the 2026 SC Awards

We’ve closed critical gaps in CTEM by connecting visibility to prioritization and adding AI-driven automated action,

March 18, 2026

Datamax Inc. Launches ActaMSP Website, Introducing a Dedicated Brand for Its Long-Standing Managed IT Services

Datamax Inc. Launches ActaMSP Website, Introducing a Dedicated Brand for Its Long-Standing Managed IT Services

ActaMSP launches to deliver proactive managed IT services, cybersecurity, and IT support for small businesses and local

March 18, 2026

KC-135 Refueling Tanker Military Veteran & Author Captain Mama at Women in Aviation meetup in Grapevine, TX This Week

KC-135 Refueling Tanker Military Veteran & Author Captain Mama at Women in Aviation meetup in Grapevine, TX This Week

Air Force Aerial Refueling Veteran & Award-Winning Children's Aviation Book Series Author Graciela Tiscareño-Sato

March 18, 2026

Hollywood Icons: Barbara Luna, Ruta Lee, Gigi Perreau, Attended Charmaine Blake Oscar Viewing

Hollywood Icons: Barbara Luna, Ruta Lee, Gigi Perreau, Attended Charmaine Blake Oscar Viewing

BEVERLY HILLS, CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Hollywood Icons Gather to Honor Eric Roberts at

March 18, 2026

Marie Smith Launches Nashville Women’s Networking Series

Marie Smith Launches Nashville Women’s Networking Series

Monthly Experiences Blend Connection, Play And Conversation For Women Seeking Community Virtual spaces have opened a

March 18, 2026

PointGuard AI Unveils MCP Security Gateway to Secure Autonomous AI Agents

PointGuard AI Unveils MCP Security Gateway to Secure Autonomous AI Agents

Zero-trust authorization, contextual security, and built-in guardrails bring governance to agentic AI The MCP Security

March 18, 2026

Tyson Group Launches High-Performance Sales Coaching Program to Turn Training Into Measurable Performance Gains

Tyson Group Launches High-Performance Sales Coaching Program to Turn Training Into Measurable Performance Gains

Many companies invest significantly in training their sales teams, but the real multiplier of performance is what

March 18, 2026

Governing and Center for Digital Government Launch National Innovation Council for the Leaders Running America’s Cities

Governing and Center for Digital Government Launch National Innovation Council for the Leaders Running America’s Cities

New City Manager Innovation Council gives leaders and private-sector partners a shared space to drive better outcomes

March 18, 2026

Consumers Credit Union Awarded Great Place To Work Certification™ for Fourth Consecutive Year

Consumers Credit Union Awarded Great Place To Work Certification™ for Fourth Consecutive Year

The Great Place To Work Certification is a tremendous honor that reflects our commitment to fully supporting our

March 18, 2026

Omega World Travel Advances Group Air and Meetings & Events Capabilities through Strategic Partnership with AMGiNE

Omega World Travel Advances Group Air and Meetings & Events Capabilities through Strategic Partnership with AMGiNE

Omega partners with AMGiNE to automate group air and streamline Meetings & Events travel This partnership gives our

March 18, 2026

Textellent Introduces Messaging Automation That Lets Headquarters Control Timing While Locations Customize Content

Textellent Introduces Messaging Automation That Lets Headquarters Control Timing While Locations Customize Content

New feature for multi-location brands that combines corporate control with franchisee-level messaging flexibility for

March 18, 2026

Sentry Interactive’s SDK enables mass enrollment of PKOC credentials

Sentry Interactive’s SDK enables mass enrollment of PKOC credentials

Enterprises deploying mobile and physical access credentials will soon be able to enroll them at scale using open

March 18, 2026

New Medicare Advantage Pilot Links Proactive Geriatric Mental Health Care to Reduced Hospitalizations

New Medicare Advantage Pilot Links Proactive Geriatric Mental Health Care to Reduced Hospitalizations

VNS Health And Vitalic Release Early Findings From a Telehealth-Based Behavioral Health Program Targeting High-Risk

March 18, 2026

Power Star Entertainment’s International Creative THINK TANK Unveils ‘Hello Dear… I’m Mother Nature’

Power Star Entertainment’s International Creative THINK TANK Unveils ‘Hello Dear… I’m Mother Nature’

An original family fantasy film treatment following a family’s journey through a magical realm guided by Mother Nature.

March 18, 2026

Reco Launches Industry-First AI Agent Security to Tackle Agent Sprawl Across SaaS

Reco Launches Industry-First AI Agent Security to Tackle Agent Sprawl Across SaaS

New capability gives security teams visibility and control over AI agents operating across their SaaS environment.

March 18, 2026

NIA Appoints JF Roy as Chief Operations Officer

NIA Appoints JF Roy as Chief Operations Officer

JF Roy becomes NIA’s first COO, continuing as CIO and leading key operations to advance the organization’s mission and

March 18, 2026

SEOPS to Deploy 19 Customer Payloads on Transporter-16 Rideshare Mission

SEOPS to Deploy 19 Customer Payloads on Transporter-16 Rideshare Mission

Manifest includes organizations from 13 countries, spanning diverse missions — communications, IoT, remote sensing,

March 18, 2026

VastSolutionsGroup.com Launches ‘Vast Q,’ a Quantum-Powered Financial Optimization Platform for Entrepreneurs

VastSolutionsGroup.com Launches ‘Vast Q,’ a Quantum-Powered Financial Optimization Platform for Entrepreneurs

New Quantum-as-a-Service platform helps entrepreneurs analyze complex tax, investment, and financial decisions faster

March 18, 2026

Hypnotist and Energy Healer Julia Nieckarz of BoChiMo Recently Featured on Close Up Radio

Hypnotist and Energy Healer Julia Nieckarz of BoChiMo Recently Featured on Close Up Radio

TERRACE, BRITISH COLUMBIA, CANADA, March 18, 2026 /EINPresswire.com/ — Albert Einstein famously said that “The

March 18, 2026

Honored Lawyer and Family Law Expert Philip A. Greenberg Recently Featured on Close Up Radio

Honored Lawyer and Family Law Expert Philip A. Greenberg Recently Featured on Close Up Radio

NEW YORK, NY, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Philip A. Greenberg is a distinguished Family Law

March 18, 2026

Remake Version ‘DRAGON QUEST ISLAND: Ancient Demon Lord and Guided Adventurers’ Opens Apr 24, 2026; ‘Thank You, Zoma’

Remake Version ‘DRAGON QUEST ISLAND: Ancient Demon Lord and Guided Adventurers’ Opens Apr 24, 2026; ‘Thank You, Zoma’

AWAJI, JAPAN, March 18, 2026 /EINPresswire.com/ — At the popular attraction “Dragon Quest Island,” located within the

March 18, 2026

Morphisec Unveils Adaptive  AI  Defense — Multi‑Layered Ransomware Protection for the AI Era

Morphisec Unveils Adaptive  AI  Defense — Multi‑Layered Ransomware Protection for the AI Era

First‑of‑its‑kind Preemptive Cyber Defense Platform Provides Visibility into Shadow AI, Fortifies Endpoints, and Stops

March 18, 2026

NEOX Networks Showcases Next-Generation Network Visibility Solutions at RSA Conference 2026

NEOX Networks Showcases Next-Generation Network Visibility Solutions at RSA Conference 2026

Visitors Invited to Experience Precision Detection for Modern Cyber Threats at Network Level at Booth N-5469 SANTA

March 18, 2026

Red Piranha Introduces Crystal Eye 6.0 with Enhanced Performance and Security Capabilities

Red Piranha Introduces Crystal Eye 6.0 with Enhanced Performance and Security Capabilities

Latest release delivers deployment automation, enhanced security controls, and up to 30% performance gains, alongside

March 18, 2026

Salt Security Launches Industry’s First Agentic Security Platform for the AI Stack Across LLMs, MCP Servers and APIs

Salt Security Launches Industry’s First Agentic Security Platform for the AI Stack Across LLMs, MCP Servers and APIs

PALO ALTO, CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — New platform gives enterprises full visibility and

March 18, 2026

New Data at ACC.26 Demonstrating UltraSight™ AI Enables Non-Experts to Perform Diagnostic Cardiac Ultrasound

New Data at ACC.26 Demonstrating UltraSight™ AI Enables Non-Experts to Perform Diagnostic Cardiac Ultrasound

Six studies in collaboration with Mayo Clinic confirm the UltraSight™ Echosystem enables non-expert clinicians to

March 18, 2026

Same-Day Dental Crowns Bring Faster, Comfortable Smile Restoration to Bixby Knolls Patients

Same-Day Dental Crowns Bring Faster, Comfortable Smile Restoration to Bixby Knolls Patients

BIXBY KNOLLS, CA, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Patients in Bixby Knolls and North Long Beach now

March 18, 2026

Titan Pest Services Introduces Advanced Termite Control Solutions for Property Protection

Titan Pest Services Introduces Advanced Termite Control Solutions for Property Protection

Titan Pest Services introduces advanced termite control solutions to help protect homes and businesses with effective,

March 18, 2026

Cabinet & Counter Expo Showcases Innovative Kitchen Cabinet Refacing Solutions for Cost-Effective Remodeling

Cabinet & Counter Expo Showcases Innovative Kitchen Cabinet Refacing Solutions for Cost-Effective Remodeling

Cabinet & Counter Expo highlights innovative kitchen cabinet refacing solutions that deliver a stylish, affordable,

March 18, 2026

Energy infrastructure boom drives demand as TreadStone Technologies adds veteran tech executive Carl D. Glaeser to board

Energy infrastructure boom drives demand as TreadStone Technologies adds veteran tech executive Carl D. Glaeser to board

Palladian Capital Partners co-founder helps TreadStone scale advanced materials platform supporting hydrogen, grid

March 18, 2026

RadSite to Host Webinar on Promoting Radiology Technologist Skill Quantification: From Competency to Consistency

RadSite to Host Webinar on Promoting Radiology Technologist Skill Quantification: From Competency to Consistency

RadSite to Host Complimentary Session on March 25 As imaging technology and workflows continue to evolve, organizations

March 18, 2026

Apogee Professionals Launches to Provide Comprehensive Wealth and Life Advisory Services for Athletes and Their Families

Apogee Professionals Launches to Provide Comprehensive Wealth and Life Advisory Services for Athletes and Their Families

Former Collegiate and Professional Athletes Launch Specialized Firm Offering "Play with Heart. Rest with Confidence.”

March 18, 2026

‘Voted Best’ Garage Door Repair Pasadena Expands Rapid Fleet

‘Voted Best’ Garage Door Repair Pasadena Expands Rapid Fleet

"Voted Best garage door company Pasadena," we are expanding our rapid response fleet to provide 24/7 emergency repairs

March 18, 2026

CatalystIQ and Halpern Advisory Merge to Form Gate City Advisory

CatalystIQ and Halpern Advisory Merge to Form Gate City Advisory

Merger of equals creates a new Atlanta-based firm combining transaction advisory, CFO services, and AI-powered

March 18, 2026

Sonoma Pharmaceuticals Announces Launch of New Dermatology Product Line under Person & Covey’s Aquanil Brand for Sensitive Skin

Sonoma Pharmaceuticals Announces Launch of New Dermatology Product Line under Person & Covey’s Aquanil Brand for Sensitive Skin

BOULDER, CO / ACCESS Newswire / March 18, 2026 / Sonoma Pharmaceuticals, Inc. (Nasdaq:SNOA), a global healthcare leader

March 18, 2026

Three New Courses for Engineering CE/PDH Make Learning Purposeful and Actionable

Three New Courses for Engineering CE/PDH Make Learning Purposeful and Actionable

CE From Amber Book is Structured for How Engineers Want to Grow and Accelerate Their Careers BLACKSBURG, VA / ACCESS

March 18, 2026

FDA Feedback Supports Extension Phase for Jaguar Health’s Clinical Trial of Crofelemer for Treatment of Microvillus Inclusion Disease (MVID)

FDA Feedback Supports Extension Phase for Jaguar Health’s Clinical Trial of Crofelemer for Treatment of Microvillus Inclusion Disease (MVID)

MVID has a lethal natural history requiring life-sustaining parenteral support (PS), which includes total parenteral

March 18, 2026

Mercury CEO Josh Medow Named “Rising Star” in 2026 Pros to Know Awards by Supply & Demand Chain Executive

Mercury CEO Josh Medow Named “Rising Star” in 2026 Pros to Know Awards by Supply & Demand Chain Executive

The 2026 Pros to Know Awards recognizes outstanding executives who serve as an example for other leaders looking to

March 18, 2026