OpenClaw AI tools deliver crypto-stealing malware
OpenClaw is an AI assistant that can act on your files, chats, and terminal commands. Attackers hid malware in over 350 fake add-ons for it, tricking people into installing a data-stealing program that raids crypto wallets, browsers, and developer logins.
- Report priority
- High
- Targets
- ClawHub+5 more
How it works
Attackers uploaded more than 350 fake add-ons, called skills, to OpenClaw's ClawHub marketplace using names that copied real developer, crypto, and automation tools, then had the AI agent tell the person installing it to run a supposed security requirement named AuthTool, which actually downloaded the NovaStealer malware.
What to do
Check whether you or your team installed an OpenClaw skill such as clawhubb, clawhub-cli, or openclawcli, or ran a Base64-encoded terminal command or opened a ZIP file that an OpenClaw agent told you to install as AuthTool. This is a poisoned-marketplace campaign, not a specific software version bug.
Remove any suspicious ClawHub skill, never run terminal commands or open files an AI agent tells you to install without checking them yourself, and if you already ran one, change your crypto wallet, browser, SSH, and cloud passwords and move wallet funds to a new wallet.
Technical details
Affected software: ClawHub, NovaStealer, MetaMask, Phantom, Exodus, Electrum
Someone searches ClawHub for a crypto automation skill and installs one of the fake packages. The skill tells the OpenClaw agent to instruct the user to install AuthTool, a supposed security requirement. On Windows the person opens a password-protected ZIP file, and on macOS or Linux they paste a Base64-encoded command into their terminal. That command downloads NovaStealer, which scans the machine for more than 60 crypto wallets and copies passwords, browser data, SSH keys, and cloud credentials.
ClawHavoc relies on social engineering rather than a software exploit. Malicious ClawHub skills instruct the OpenClaw agent to prompt the user to install AuthTool, a fake security tool. Windows victims get a password-protected ZIP; macOS and Linux victims paste a Base64-encoded command that fetches NovaStealer v2, part of the Atomic macOS Stealer family, which harvests data from more than 60 crypto wallets plus browser cookies, SSH keys, cloud credentials, and .env files. Trellix also flags indirect prompt injection, where hidden instructions in documents or web pages an agent reads could trigger similar unauthorized downloads or commands, since OpenClaw agents can read clipboards, download and run files, and create scheduled tasks.
References
- trellix.com · when-agents-go-rogue-openclaw-supply-chain-crisis Cyber Security News
- ppl-ai-file-upload.s3.amazonaws.com · Hackers-Weaponize-OpenClaw-AI-Agents-to-Push-Malware-and-Steal-Crypto-Wallets.pdf Cyber Security News
- any.run · threat-intelligence-lookup Cyber Security News
- thehackernews.com · how-mcp-servers-can-expose-enterprise.html TheHackerNews
- infosecurity-magazine.com · macos-infostealer-spread-clickfix Infosecurity Magazine
- infosecurity-magazine.com · logistics-ceva-data-breach Infosecurity Magazine
- infosecurity-magazine.com · gobased-macos-malware-crypto-and Infosecurity Magazine
- infosecurity-magazine.com · fake-bank-of-america-phishing-scam Infosecurity Magazine