SlowMist reports supply chain poisoning in OpenClaw's ClawHub plugin center.

09 Feb 2026, 05:53
🥷 SlowMist reports supply chain poisoning in OpenClaw's ClawHub plugin center. Weak reviews allowed numerous malicious skills to infiltrate and spread harmful code. Koi Security scanned 2,857 skills, identifying 341 malicious ones. SlowMist analyzed over 400 IOCs, revealing organized batch attacks targeting a few fixed domains/IPs via two-stage loading, which includes initial obfuscation and dynamic payload retrieval. An example includes the "X (Twitter) Trends" skill, which hides a Base64 backdoor that downloads and executes malware to phish passwords, collect files, and upload them to C2. link