Cybercriminals are turning AI agents into a new route for malware delivery. A campaign targeting OpenClaw, an open-source platform that lets AI agents interact with files, messaging apps, and terminal commands, used poisoned marketplace packages to place data-stealing malware on victim devices.
The campaign, known as ClawHavoc, targeted OpenClaw’s ClawHub skill registry with malicious packages disguised as useful developer, crypto, and automation tools.
Victims were lured into installing fake utilities or pasting commands into a terminal, allowing attackers to download malware that can steal crypto wallets, passwords, browser data, and developer credentials.
Researchers from Trellix identified the activity while tracking critical flaws and active exploitation affecting OpenClaw deployments.
Their investigation found that the attack moved beyond a simple malicious package campaign, showing how trusted AI workflows can be abused to persuade users and run harmful commands on systems with broad permissions.
Trellix’s report shared with Cyber Security News (CSN) details the observed infection chain and defensive measures. The risk is significant because an AI agent can be connected to local files, cloud accounts, chats, and command-line tools.
If an attacker controls a skill or slips hidden instructions into content an agent reads, the AI can become an unwitting helper in data theft or malware delivery.
Recent reporting on OpenClaw marketplace supply chain risks shows why agent permissions now deserve the same scrutiny as any privileged application.
Attackers flooded ClawHub with more than 350 malicious skills, according to Trellix. They used names resembling legitimate tools, including clawhubb, clawhub-cli, and openclawcli, while targeting people searching for crypto automation, software updates, and social media integrations.
Some packages were artificially boosted to appear popular or trustworthy. The malicious instructions used a ClickFix-style lure. Instead of directly exploiting a software flaw, the package told the AI agent to instruct its user to install a supposed security requirement named AuthTool.
On Windows, victims were directed to a password-protected ZIP archive. On macOS and Linux, they were encouraged to paste a Base64-encoded terminal command.
That command fetched NovaStealer v2, a macOS-focused information stealer linked to the Atomic macOS Stealer family.
The malware searches for data from more than 60 crypto wallets, including MetaMask, Phantom, Exodus, and Electrum, while also collecting browser cookies, login information, SSH keys, cloud credentials, and .env files.
The campaign follows a broader pattern seen in attacks against Apple users, where deceptive prompts push victims into running terminal commands themselves.
In a recent ClickFix malware delivery campaign, attackers similarly used fake updates and social-engineering prompts to target browser data, credentials, and cryptocurrency wallets.
Trellix also warned that poisoned skills are only one part of the problem. Attackers can use indirect prompt injection, where hidden instructions are placed in emails, documents, web pages, or chat messages that an AI agent is asked to process.
The agent may then treat attacker-controlled text as an instruction rather than untrusted content. In testing, researchers found that OpenClaw could read clipboard contents, download and execute files, and create scheduled tasks when given commands.
Such capabilities are useful for automation, but they become dangerous when an agent has unrestricted access to the operating system and trusts malicious instructions.
Similar prompt injection attacks against coding agents have demonstrated that hostile repository content can lead to unauthorized command execution.
Organizations running OpenClaw should update older deployments, avoid using the platform on primary workstations, and place it on isolated devices or virtual servers.
They should restrict network access, connect only low-risk accounts, audit installed skills, and watch for suspicious child processes such as node.exe launching PowerShell, curl, nc.exe, or schtasks.exe.
Security teams should also treat AI-generated tool requests as untrusted until verified. Restricting agent permissions, requiring approval before sensitive actions, and separating external content from privileged commands can reduce exposure.
Guidance from related AI prompt injection research similarly stresses allowlisted tools, least-privilege credentials, approval gates, and monitoring for unusual access to secrets.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IPv4 | 91.92.242.30 | Primary payload delivery server associated with ClawHavoc and NovaStealer activity |
| IPv4 | 95.92.242.30 | Secondary command-and-control infrastructure associated with the campaign |
| SHA-256 | 998c38b430097479b015a68d9435dc5b98684119739572a4dff11e085881187e | NovaStealer v2 macOS binary |
| SHA-256 | 17703b3d5e8e1fe69d6a6c78a240d8c84b32465fe62bed5610fb29335fe42283 | Windows VMProtect-packed infostealer sample |
| File path | $TMPDIR/dx2w* | Command staging path for macOS payload execution |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…
Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents…