Cyber Security News

Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets

Cybercriminals are turning AI agents into a new route for malware delivery. A campaign targeting OpenClaw, an open-source platform that lets AI agents interact with files, messaging apps, and terminal commands, used poisoned marketplace packages to place data-stealing malware on victim devices.

The campaign, known as ClawHavoc, targeted OpenClaw’s ClawHub skill registry with malicious packages disguised as useful developer, crypto, and automation tools.

Victims were lured into installing fake utilities or pasting commands into a terminal, allowing attackers to download malware that can steal crypto wallets, passwords, browser data, and developer credentials.

Researchers from Trellix identified the activity while tracking critical flaws and active exploitation affecting OpenClaw deployments.

Their investigation found that the attack moved beyond a simple malicious package campaign, showing how trusted AI workflows can be abused to persuade users and run harmful commands on systems with broad permissions. 

Trellix’s report shared with Cyber Security News (CSN) details the observed infection chain and defensive measures. The risk is significant because an AI agent can be connected to local files, cloud accounts, chats, and command-line tools.

If an attacker controls a skill or slips hidden instructions into content an agent reads, the AI can become an unwitting helper in data theft or malware delivery.

Recent reporting on OpenClaw marketplace supply chain risks shows why agent permissions now deserve the same scrutiny as any privileged application.

Hackers Weaponize OpenClaw AI Agents

Attackers flooded ClawHub with more than 350 malicious skills, according to Trellix. They used names resembling legitimate tools, including clawhubbclawhub-cli, and openclawcli, while targeting people searching for crypto automation, software updates, and social media integrations.

Some packages were artificially boosted to appear popular or trustworthy. The malicious instructions used a ClickFix-style lure. Instead of directly exploiting a software flaw, the package told the AI agent to instruct its user to install a supposed security requirement named AuthTool.

On Windows, victims were directed to a password-protected ZIP archive. On macOS and Linux, they were encouraged to paste a Base64-encoded terminal command.

That command fetched NovaStealer v2, a macOS-focused information stealer linked to the Atomic macOS Stealer family.

The malware searches for data from more than 60 crypto wallets, including MetaMask, Phantom, Exodus, and Electrum, while also collecting browser cookies, login information, SSH keys, cloud credentials, and .env files.

Deceptive ClickFix instruction pattern within a malicious skill (Source – Trellix)

The campaign follows a broader pattern seen in attacks against Apple users, where deceptive prompts push victims into running terminal commands themselves.

In a recent ClickFix malware delivery campaign, attackers similarly used fake updates and social-engineering prompts to target browser data, credentials, and cryptocurrency wallets.

Prompt Injection Raises the Stakes

Trellix also warned that poisoned skills are only one part of the problem. Attackers can use indirect prompt injection, where hidden instructions are placed in emails, documents, web pages, or chat messages that an AI agent is asked to process.

The agent may then treat attacker-controlled text as an instruction rather than untrusted content. In testing, researchers found that OpenClaw could read clipboard contents, download and execute files, and create scheduled tasks when given commands.

Such capabilities are useful for automation, but they become dangerous when an agent has unrestricted access to the operating system and trusts malicious instructions.

Similar prompt injection attacks against coding agents have demonstrated that hostile repository content can lead to unauthorized command execution.

Organizations running OpenClaw should update older deployments, avoid using the platform on primary workstations, and place it on isolated devices or virtual servers.

Cross-platform clipboard access enabling potential data exfiltration (Source – Trellix)

They should restrict network access, connect only low-risk accounts, audit installed skills, and watch for suspicious child processes such as node.exe launching PowerShell, curlnc.exe, or schtasks.exe.

Security teams should also treat AI-generated tool requests as untrusted until verified. Restricting agent permissions, requiring approval before sensitive actions, and separating external content from privileged commands can reduce exposure.

Guidance from related AI prompt injection research similarly stresses allowlisted tools, least-privilege credentials, approval gates, and monitoring for unusual access to secrets.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IPv491.92.242.30Primary payload delivery server associated with ClawHavoc and NovaStealer activity
IPv495.92.242.30Secondary command-and-control infrastructure associated with the campaign
SHA-256998c38b430097479b015a68d9435dc5b98684119739572a4dff11e085881187eNovaStealer v2 macOS binary
SHA-25617703b3d5e8e1fe69d6a6c78a240d8c84b32465fe62bed5610fb29335fe42283Windows VMProtect-packed infostealer sample
File path$TMPDIR/dx2w*Command staging path for macOS payload execution

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

37 minutes ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

1 hour ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

1 hour ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

3 hours ago

Hackers Use Fake Student Resume to Secretly Install Malware on Researchers’ Computers

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

4 hours ago

Russian University Leak Exposes GRU Cyber Training Pipeline Behind APT28 and Sandworm

Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents…

5 hours ago