This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Turn1 Unveils 2025–2026 Performance Upgrades for Ducati, Aprilia, and BMW Motorcycles

Turn1 Unveils 2025–2026 Performance Upgrades for Ducati, Aprilia, and BMW Motorcycles

Premium carbon fiber components designed to improve performance, style, and the overall riding experience Turn1

March 18, 2026

AI Energy Conference 3 to Highlight AI-Driven Energy and Data Center Growth Across the Appalachian Basin

AI Energy Conference 3 to Highlight AI-Driven Energy and Data Center Growth Across the Appalachian Basin

AI Energy Conference 3 is designed to give companies the actionable information they need to participate in this

March 18, 2026

MoodRx LLC Expands Insurance Coverage and Specialized Mental Health Services Across Pennsylvania

MoodRx LLC Expands Insurance Coverage and Specialized Mental Health Services Across Pennsylvania

Expanding coverage, lowering costs, and age-specific therapy models—MoodRx is redefining how Pennsylvanians access

March 18, 2026

Adoption of HOA Start’s Communications Suite Grows as Boards Modernize Resident Communication

Adoption of HOA Start’s Communications Suite Grows as Boards Modernize Resident Communication

As more associations adopt digital communication tools, boards reach residents faster, reducing missed messages, and

March 18, 2026

Waratek Redefines Secure Development with Launch of Waratek IAST at JavaOne 2026

Waratek Redefines Secure Development with Launch of Waratek IAST at JavaOne 2026

AI-assisted code speeds development, but introduces vulnerabilities at an alarming rate. Waratek IAST reports flaws

March 18, 2026

Whey Water Announces May 2026 Launch of Sparkling Protein Beverage

Whey Water Announces May 2026 Launch of Sparkling Protein Beverage

Launching in May 2026, Whey Water offers 18g whey protein isolate per can, sweetened with stevia and monk fruit, with

March 18, 2026

Independent Film DARKLIGHT Launches on Seed&Spark Exploring Identity and Transformation

Independent Film DARKLIGHT Launches on Seed&Spark Exploring Identity and Transformation

An independent film project using cinematic storytelling to explore identity, transformation, and emotional depth. LOS

March 18, 2026

New Survey Reveals Most Homeowners Are Leaving Valuable Jewelry Underprotected

New Survey Reveals Most Homeowners Are Leaving Valuable Jewelry Underprotected

BriteCo Research Shows Widespread Misunderstanding About Jewelry Coverage in Homeowners Insurance Policies Many

March 18, 2026

ProHance Launches Comprehensive Global Productivity Benchmarking Report Based on Three-Year Data Set

ProHance Launches Comprehensive Global Productivity Benchmarking Report Based on Three-Year Data Set

Reveals key productivity benchmarks, workforce trends, and actionable insights to help enterprises optimize performance

March 18, 2026

Medicus Pharma To Discuss Positive Skinject(R) Phase 2 Topline Results In Fireside Chat Hosted By Brookline Capital Markets Biotechnology Equity Research Analyst

Medicus Pharma To Discuss Positive Skinject(R) Phase 2 Topline Results In Fireside Chat Hosted By Brookline Capital Markets Biotechnology Equity Research Analyst

Phase 2 Study Demonstrated 73% clinical Clearance in the 200-µg Arm suggests that ~3 out of 4 treated lesions may allow

March 18, 2026

Nextech3D.ai Division Achieves Profitability, Signaling Operating Leverage, Margin Expansion and Accelerating Enterprise Momentum

Nextech3D.ai Division Achieves Profitability, Signaling Operating Leverage, Margin Expansion and Accelerating Enterprise Momentum

First Full Month of Post-Acquisition Profitability Highlights Platform Scale, Improving Margins and a Clear Path Toward

March 18, 2026

TGI Solar Power Group Inc. Announces Strategic Alliance With MetaSense Inc. to Scale Human Capital for Global Energy and Technology Projects

TGI Solar Power Group Inc. Announces Strategic Alliance With MetaSense Inc. to Scale Human Capital for Global Energy and Technology Projects

Redefining Human Capital Management Across Aviation, Nuclear Power, AI, Robotics and Agentic AI MIAMI, FL / ACCESS

March 18, 2026

#paid and Pinterest Announce Strategic Partnership to Power Creator-Led Commerce at the Moment of Decision

#paid and Pinterest Announce Strategic Partnership to Power Creator-Led Commerce at the Moment of Decision

New Partnership Connects Brands With Consumers at the Point of Decision Through Creator-Led Media SAN FRANCISCO, CA AND

March 18, 2026

App Orchid Enables Role-based Control of LLMs in Agentic BI

App Orchid Enables Role-based Control of LLMs in Agentic BI

New release introduces role-based AI guardrails and mobile Easy Answers experience SAN RAMON, CA / ACCESS Newswire /

March 18, 2026

SocialPost.ai Deploys AI Agents Working Together to Run Company Operations

SocialPost.ai Deploys AI Agents Working Together to Run Company Operations

Startup becomes AI-native using autonomous AI agents to run operations 24/7. MIAMI, FL / ACCESS Newswire / March 18,

March 18, 2026

More Americans Are Tapping Home Equity to Pay IRS Debt – Clear Start Tax Explains the Risks Behind the Trend

More Americans Are Tapping Home Equity to Pay IRS Debt – Clear Start Tax Explains the Risks Behind the Trend

Rising tax debt and high consumer interest rates are pushing some homeowners to use home equity loans to settle IRS

March 18, 2026

Accurate’s Identity Verification Helps Employers Combat Rising Candidate Fraud

Accurate’s Identity Verification Helps Employers Combat Rising Candidate Fraud

Enhanced solution verifies government-issued IDs and confirms candidate identity in seconds IRVINE, CA / ACCESS

March 18, 2026

CCS Named Best Cyber Security & Best Computer Services in Best of Long Island 2026 for Fifth Consecutive Year

CCS Named Best Cyber Security & Best Computer Services in Best of Long Island 2026 for Fifth Consecutive Year

The award highlights CCS’s continued leadership in cyber security and technology services across the region. This

March 18, 2026

Best Garage Door Repair Long Beach”: On The Spot Announces 24/7 Expansion

Best Garage Door Repair Long Beach”: On The Spot Announces 24/7 Expansion

Voted Best Garage Door Repair Long Beach, On The Spot expands 24/7 emergency services and launches a Coastal Climate

March 18, 2026

Resource Group Holdings Plc (RGH) Expands Compliance and Regulatory Capabilities with Acquisition of RiskPod

Resource Group Holdings Plc (RGH) Expands Compliance and Regulatory Capabilities with Acquisition of RiskPod

RGH acquires RiskPod to enhance its workforce optimisation platform with tech-enabled compliance, KYC, AML and

March 18, 2026

Consumer Protection Networks Announces Partnerships with SurePay & Equity Sales Finance to Expand Client Payment Options

Consumer Protection Networks Announces Partnerships with SurePay & Equity Sales Finance to Expand Client Payment Options

Consumer Protection Networks partners with SurePay and Equity Sales Finance to offer flexible payment options for

March 18, 2026

Xcellimark Launches HubSpot Interactive Map to Enhance Location Discovery on HubSpot Websites

Xcellimark Launches HubSpot Interactive Map to Enhance Location Discovery on HubSpot Websites

New interactive location map module available in the HubSpot Marketplace helps businesses showcase multiple locations

March 18, 2026

ibml Announces ibml Coretex Platform – AI-Powered IDP Software Built for Speed, Accuracy, and Control

ibml Announces ibml Coretex Platform – AI-Powered IDP Software Built for Speed, Accuracy, and Control

On Premise private AI, natural-language setup, and confidence-driven human review help enterprises turn complex

March 18, 2026

Western Timber Frame Builds Timber Structures With Cabinetry Precision, Patented Engineering, And Integrated Power

Western Timber Frame Builds Timber Structures With Cabinetry Precision, Patented Engineering, And Integrated Power

Based in Payson, Utah, the company has delivered 6,000+ custom pergolas, pavilions, and cabanas nationwide using a

March 18, 2026

Influential Women Features Lora L. Morrison: End-of-Life Doula And Founder Of Dignity Life & Legacy Services

Influential Women Features Lora L. Morrison: End-of-Life Doula And Founder Of Dignity Life & Legacy Services

ZEPHYRHILLS, FL, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Providing Compassionate, Holistic Support for

March 18, 2026

Influential Women Showcases Stephanie Littlejohn: Assistant Controller And Accounting Professional With 25+ Years

Influential Women Showcases Stephanie Littlejohn: Assistant Controller And Accounting Professional With 25+ Years

WICHITA, KS, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Seasoned Financial Leader Providing Expertise in

March 18, 2026

Channel Twin Launches to Solve the Pain of Video Creation and Consistency

Channel Twin Launches to Solve the Pain of Video Creation and Consistency

AI-powered platform helps entrepreneurs and brands create short-form avatar video without filming every week, editing

March 18, 2026

Influential Women Features Rebecca Blacketer York: Product Manager at LinenMaster by TEXO

Influential Women Features Rebecca Blacketer York: Product Manager at LinenMaster by TEXO

EXETER, NH, UNITED STATES, March 18, 2026 /EINPresswire.com/ — Delivering Innovative Software Solutions and

March 18, 2026

Golpo AI Launches Golpo Canvas and Pen-in-Hand Animation to Turn Documents into Whiteboard Videos in Minutes

Golpo AI Launches Golpo Canvas and Pen-in-Hand Animation to Turn Documents into Whiteboard Videos in Minutes

Golpo Canvas + Pen in Hand Animation just dropped. Turn onboarding docs, lesson plans, or marketing briefs into

March 18, 2026

Nordic MSPs Can Now Access Heimdal’s Unified Security and Compliance Platform Through Elovade

Nordic MSPs Can Now Access Heimdal’s Unified Security and Compliance Platform Through Elovade

COPENHAGEN, DENMARK, March 18, 2026 /EINPresswire.com/ — Heimdal has appointed Elovade as its official distributor in

March 18, 2026

CHEMEON and SurTec Form Strategic Alliance in Global Surface Technology Market

CHEMEON and SurTec Form Strategic Alliance in Global Surface Technology Market

Transatlantic Partnership Strengthens High-Performance Surface Treatment Solutions MINDEN, NV, UNITED STATES, March 18,

March 18, 2026

Precise and Clean Joints, Soldering Under High Vacuum Makes This Possible

Precise and Clean Joints, Soldering Under High Vacuum Makes This Possible

Conventional soldering methods quickly reach their limits when joining carbides, diamonds or ceramics. For us, Pfeiffer

March 18, 2026

Inventus Reports $1.16 Million in Gold Sales and 102% Return on Bulk Sample Cost at Pardo

Inventus Reports $1.16 Million in Gold Sales and 102% Return on Bulk Sample Cost at Pardo

TORONTO, ON / ACCESS Newswire / March 18, 2026 / Inventus Mining Corp. (TSXV:IVS) ("Inventus" or the "Company") is

March 18, 2026

Gibbs Landscape Company Wins 2026 Consumer Choice Award in Atlanta

Gibbs Landscape Company Wins 2026 Consumer Choice Award in Atlanta

ATLANTA, GA / ACCESS Newswire / March 18, 2026 / Gibbs Landscape Company has been named the 2026 Consumer Choice Award

March 18, 2026

Modern Mingle Wins 2026 Consumer Choice Award for Dating Services in San Antonio

Modern Mingle Wins 2026 Consumer Choice Award for Dating Services in San Antonio

SAN ANTONIO, TX / ACCESS Newswire / March 18, 2026 / Modern Mingle, San Antonio's premier matchmaking and singles

March 18, 2026

One Hour Heating & Air Conditioning Wins 2026 Consumer Choice Award for Air Conditioning and Heating Contractor in Charlotte

One Hour Heating & Air Conditioning Wins 2026 Consumer Choice Award for Air Conditioning and Heating Contractor in Charlotte

CHARLOTTE, NC / ACCESS Newswire / March 18, 2026 / One Hour Heating & Air Conditioning, a locally owned HVAC

March 18, 2026

Jessica Design Recognized with Consumer Choice Award for Graphic & Web Design in Hamilton

Jessica Design Recognized with Consumer Choice Award for Graphic & Web Design in Hamilton

HAMILTON, ON / ACCESS Newswire / March 18, 2026 / Jessica Design has been recognized with the 2026 Consumer Choice

March 18, 2026

Home-Tite Pest Control & Proofing Wins 2026 Consumer Choice Award for Pest Control in Waterloo

Home-Tite Pest Control & Proofing Wins 2026 Consumer Choice Award for Pest Control in Waterloo

WATERLOO, ON / ACCESS Newswire / March 18, 2026 / Home-Tite Pest Control & Proofing, a trusted provider of

March 18, 2026

Pro Scaffold Inc Recognized with Consumer Choice Award for Scaffolding in London and Greater Region

Pro Scaffold Inc Recognized with Consumer Choice Award for Scaffolding in London and Greater Region

LONDON, ON / ACCESS Newswire / March 18, 2026 / Pro Scaffold Inc has been named the 2026 Consumer Choice Award winner

March 18, 2026

North Shore to List on the OTCQB

North Shore to List on the OTCQB

VANCOUVER, BC / ACCESS Newswire / March 18, 2026 / North Shore Uranium Ltd. (TSX-V:NSU) ("North Shore" or the

March 18, 2026