Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    The Korg Handytraxx Play finally got me learning to scratch

    The Korg Handytraxx Play finally got me learning to scratch

    April 1, 2026
    These Raspberry Pi price hikes are no joke

    These Raspberry Pi price hikes are no joke

    April 1, 2026
    A YouTuber channeled his distaste for the PS5’s design into slick console covers

    A YouTuber channeled his distaste for the PS5’s design into slick console covers

    April 1, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » OpenClaw’s AI ‘skill’ extensions are a security nightmare
    News

    OpenClaw’s AI ‘skill’ extensions are a security nightmare

    News RoomBy News RoomFebruary 4, 20262 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    OpenClaw’s AI ‘skill’ extensions are a security nightmare

    OpenClaw, the AI agent that has exploded in popularity over the past week, is raising new security concerns after researchers uncovered malware in hundreds of user-submitted “skill” add-ons on its marketplace. In a post on Monday, 1Password product VP Jason Meller says OpenClaw’s skill hub has become “an attack surface,” with the most-downloaded add-on serving as a “malware delivery vehicle.”

    OpenClaw — first called Clawdbot, then Moltbot — is billed as an AI agent that “actually does things,” such as managing your calendar, checking in for flights, cleaning out your inbox, and more. It runs locally on devices, and users can interact with the AI assistant through messaging apps like WhatsApp, Telegram, iMessage, and others. But some users are giving OpenClaw the ability to access their entire device, allowing it to read and write files, execute scripts, and run shell commands.

    While this kind of access poses risks on its own, malware disguised as skills that are supposed to enhance OpenClaw’s capabilities only contribute to concerns. OpenSourceMalware, a platform that tracks the presence of malware across the open-source ecosystem, found that 28 malicious skills were published on the ClawHub skill marketplace between January 27th and 29th, in addition to 386 malicious add-ons that were uploaded between January 31st and February 2nd.

    OpenSourceMalware says the skills “masquerade as cryptocurrency trading automation tools and deliver information-stealing malware” and manipulate users into executing malicious code that “steals crypto assets like exchange API keys, wallet private keys, SSH credentials, and browser passwords.”

    Meller notes that OpenClaw’s skills are often uploaded as markdown files, which could contain malicious instructions for both users and the AI agent. That’s what he found when examining one of ClawHub’s most popular add-ons, a “Twitter” skill containing instructions for users to navigate to a link “designed to get the agent to run a command” that downloads infostealing malware.

    OpenClaw’s creator, Peter Steinberger, is working to address some of these risks, as ClawHub now requires users to have a GitHub account that’s at least one week old to publish a skill. There’s also a new way to report skills, though this doesn’t remove the possibility of malware sneaking onto the platform.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleThis Town, 2.0
    Next Article Google’s annual revenue tops $400 billion for the first time

    Related Posts

    These Raspberry Pi price hikes are no joke

    These Raspberry Pi price hikes are no joke

    April 1, 2026
    A YouTuber channeled his distaste for the PS5’s design into slick console covers

    A YouTuber channeled his distaste for the PS5’s design into slick console covers

    April 1, 2026
    AI can push your Stream Deck buttons for you

    AI can push your Stream Deck buttons for you

    April 1, 2026
    The latest Matter update improves camera streaming

    The latest Matter update improves camera streaming

    March 31, 2026
    Claude Code leak exposes a Tamagotchi-style ‘pet’ and an always-on agent

    Claude Code leak exposes a Tamagotchi-style ‘pet’ and an always-on agent

    March 31, 2026
    You can now use ChatGPT with Apple’s CarPlay

    You can now use ChatGPT with Apple’s CarPlay

    March 31, 2026
    Our Picks
    These Raspberry Pi price hikes are no joke

    These Raspberry Pi price hikes are no joke

    April 1, 2026
    A YouTuber channeled his distaste for the PS5’s design into slick console covers

    A YouTuber channeled his distaste for the PS5’s design into slick console covers

    April 1, 2026
    AI can push your Stream Deck buttons for you

    AI can push your Stream Deck buttons for you

    April 1, 2026
    The latest Matter update improves camera streaming

    The latest Matter update improves camera streaming

    March 31, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Claude Code leak exposes a Tamagotchi-style ‘pet’ and an always-on agent News

    Claude Code leak exposes a Tamagotchi-style ‘pet’ and an always-on agent

    By News RoomMarch 31, 2026

    After Anthropic released Claude Code’s 2.1.88 update, users quickly discovered that it contained a package…

    You can now use ChatGPT with Apple’s CarPlay

    You can now use ChatGPT with Apple’s CarPlay

    March 31, 2026
    You can grab a four-pack of Govee’s color-changing smart bulbs for just

    You can grab a four-pack of Govee’s color-changing smart bulbs for just $27

    March 31, 2026
    Anker’s power bank with built-in cables is one of my favorite gadgets, and it’s cheaper than usual

    Anker’s power bank with built-in cables is one of my favorite gadgets, and it’s cheaper than usual

    March 31, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.