This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Asian-Led NutriWorks® Uplifts Traditional Chinese Medicine’s Power & Accessible Beauty with Reflexology Foot Patches

Asian-Led NutriWorks® Uplifts Traditional Chinese Medicine’s Power & Accessible Beauty with Reflexology Foot Patches

BOCA RATON, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — As costs of living increase, Americans nationwide

March 17, 2026

Key Bridge Wireless Introduces Simplified Flat-Rate Pricing for CBRS

Key Bridge Wireless Introduces Simplified Flat-Rate Pricing for CBRS

tldr; $500 for your first 100 radios, $10 per radio thereafter. MCLEAN, VA, UNITED STATES, March 17, 2026

March 17, 2026

ACHS Announces New Marketplace Partnership with AzureWell

ACHS Announces New Marketplace Partnership with AzureWell

New ACHS–AzureWell partnership expands marketplace access, educational initiatives, and career opportunities in the

March 17, 2026

Angel Davis Brings Powerful One-Act Play ‘A Beautiful Mess’ to Los Angeles Stage This May

Angel Davis Brings Powerful One-Act Play ‘A Beautiful Mess’ to Los Angeles Stage This May

A raw, thought-provoking theatrical experience exploring grief, healing, and the unseen conversations that shape us

March 17, 2026

Computer Coach Launches AI Workforce Training Center to Prepare Professionals for the Future of Work

Computer Coach Launches AI Workforce Training Center to Prepare Professionals for the Future of Work

New AI training programs help professionals, businesses, and workforce organizations build practical artificial

March 17, 2026

I-State Truck Center in Marshfield Moving to New Facility

I-State Truck Center in Marshfield Moving to New Facility

The I-State Truck Centers location in Marshfield has moved to a new location at 2503 East Heritage Dr., Marshfield, WI

March 17, 2026

Developer James McManus Speaks Out on America Tonight Radio Alleging Fairbridge Seized Property After Term Sheet

Developer James McManus Speaks Out on America Tonight Radio Alleging Fairbridge Seized Property After Term Sheet

NEW YORK CITY, NY, UNITED STATES, March 17, 2026 /EINPresswire.com/ — New York developer James McManus discussed an

March 17, 2026

Moose Vinyl Acquires B-Side Records in Lemont, Illinois

Moose Vinyl Acquires B-Side Records in Lemont, Illinois

Popular record store to remain a community hub under new ownership CHICAGO, IL, UNITED STATES, March 17, 2026

March 17, 2026

Identity Is the Attack Surface: TraitWare Launches New Platform to Address Human and AI Identity Access and Governance.

Identity Is the Attack Surface: TraitWare Launches New Platform to Address Human and AI Identity Access and Governance.

New digital presence showcases how security leaders can eliminate credential-based attacks, adopt Phishing Resistant

March 17, 2026

Atlas Renewable Energy Appoints Esteban Uauy as Chief Financial Officer

Atlas Renewable Energy Appoints Esteban Uauy as Chief Financial Officer

Promotion follows record-setting financings and reinforces Atlas' institutional platform ahead of next growth phase.

March 17, 2026

Half of Native Hawaiian University of Hawaiʻi students experience period poverty, study reveals

Half of Native Hawaiian University of Hawaiʻi students experience period poverty, study reveals

George Mason University researchers uncover the burden of period poverty, mental health, and food and housing

March 17, 2026

Women’s History Month: Recognizing Professional Excellence at Atlas Hartmann

Women’s History Month: Recognizing Professional Excellence at Atlas Hartmann

Atlas Hartmann celebrates Women’s History Month by recognizing the contributions of women in shaping operations,

March 17, 2026

Pharmacosmos initiates phase III clinical trial of trilaciclib in limited-stage small cell lung cancer

Pharmacosmos initiates phase III clinical trial of trilaciclib in limited-stage small cell lung cancer

Pharmacosmos initiates phase III clinical trial of trilaciclib in limited-stage small cell lung cancer MORRISTOWN, NJ,

March 17, 2026

CFGMS Introduces a New ISO Manager; Ari Averyanov

CFGMS Introduces a New ISO Manager; Ari Averyanov

NEW YORK, NY, UNITED STATES, March 17, 2026 /EINPresswire.com/ — CFG Merchant Solutions® is proud to announce a new

March 17, 2026

Völur named in Thrive’s Top 50 AgTech Rising Stars for 2026 by SVG Ventures

Völur named in Thrive’s Top 50 AgTech Rising Stars for 2026 by SVG Ventures

Recognition Highlights Völur's Leadership in AI-Driven Optimization for the Meat Industry Supply Chain This recognition

March 17, 2026

BCD and EyeOTmonitor Announce Strategic Partnership Ahead of ISC West 2026

BCD and EyeOTmonitor Announce Strategic Partnership Ahead of ISC West 2026

BCD and EyeOTmonitor announce a strategic partnership delivering real-time visibility across modern video surveillance

March 17, 2026

Most Business Emails Are Indistinguishable From Phishing. SSL Dragon’s New Mark Certificates Change That

Most Business Emails Are Indistinguishable From Phishing. SSL Dragon’s New Mark Certificates Change That

With fewer than 5% of domains enforcing DMARC and BIMI adoption below 6%, SSL Dragon launches DigiCert VMC and CMC

March 17, 2026

Jason Ruedy ‘The Home Loan Arranger’ Explains How Grand Lake Investors Use DSCR Loans to Consolidate Debt

Jason Ruedy ‘The Home Loan Arranger’ Explains How Grand Lake Investors Use DSCR Loans to Consolidate Debt

Jason Ruedy “The Home Loan Arranger” Highlights DSCR Loans for Grand Lake Real Estate Investors In addition to

March 17, 2026

William Bernhardt Explores the Legal and Moral Battle Behind America’s Greatest Superhero in ‘The Superman Wars’

William Bernhardt Explores the Legal and Moral Battle Behind America’s Greatest Superhero in ‘The Superman Wars’

The award-winning author reveals the true story behind Superman’s creation and the decades-long fight for justice,

March 17, 2026

Crux Facilitates Safe Harbor Financing Between Cloudbreak and Bildmore

Crux Facilitates Safe Harbor Financing Between Cloudbreak and Bildmore

The transaction supports the safe harboring of Cloudbreak’s community solar projects across Colorado and Maryland.

March 17, 2026

Technology and AI Luminary Neal Fishman Publishes Manifesto Calling for Global Licensing and Certification of AI Systems

Technology and AI Luminary Neal Fishman Publishes Manifesto Calling for Global Licensing and Certification of AI Systems

Fishman’s manifesto draws parallels between AI governance and nuclear nonproliferation, urging nations to act before

March 17, 2026

The Crownies Launch National Creator Awards Recognizing Excellence in Social Media and Influencer Marketing

The Crownies Launch National Creator Awards Recognizing Excellence in Social Media and Influencer Marketing

Twice-Yearly Awards Program Honors Creators, Students, Agencies, and Digital Content Teams Across the United States

March 17, 2026

Brazil takes center stage at Hannover Messe 2026 with industrial innovation and sustainability focus

Brazil takes center stage at Hannover Messe 2026 with industrial innovation and sustainability focus

As the event’s partner country, Brazil reinforces its position as Latin America’s largest economy, backed by robust and

March 17, 2026

Lenoss Medical Announces Successful Close of $6 Million Growth Bridge Financing

Lenoss Medical Announces Successful Close of $6 Million Growth Bridge Financing

Funding will accelerate commercial expansion, scale operations, and further strengthen clinical data generation Seeing

March 17, 2026

Octave Holdings & Investments and Vantico Investments Acquire Randall Square as Third Acquisition in 2026

Octave Holdings & Investments and Vantico Investments Acquire Randall Square as Third Acquisition in 2026

ALPHARETTA, GA, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Octave Holdings & Investments (Octave) and

March 17, 2026

ITIL 5 Foundation Training Prepares Teams for AI Era

ITIL 5 Foundation Training Prepares Teams for AI Era

ONLC Training launches a three-day ITIL certification course helping professionals align digital service management,

March 17, 2026

New to The Street Announces Full-Scale Media Coverage of Jacob Javits Center Events Through 2027

New to The Street Announces Full-Scale Media Coverage of Jacob Javits Center Events Through 2027

NEW YORK, NY / ACCESS Newswire / March 17, 2026 / New to The Street, one of the fastest-growing global financial media

March 17, 2026

Bradford Wibsey All-On-4 Dental Implants Private Dentist Dr Carl Taylor Advises Full-Arch Replacement Consultations at Taylored Dental Care

Bradford Wibsey All-On-4 Dental Implants Private Dentist Dr Carl Taylor Advises Full-Arch Replacement Consultations at Taylored Dental Care

Bradford, England – March 17, 2026 – PRESSADVANTAGE – Taylored Dental Care Wibsey has confirmed the availability of

March 17, 2026

Silverback AI Chatbot Announces Expanded AI Chatbot Capabilities for Structured Digital Communication and Automated Interaction

Silverback AI Chatbot Announces Expanded AI Chatbot Capabilities for Structured Digital Communication and Automated Interaction

New York, New York – March 17, 2026 – PRESSADVANTAGE – Silverback AI Chatbot has released an announcement outlining the

March 17, 2026

Big Easy Painters Releases Detailed Guide on Selecting the Right Paint for Kitchen Cabinets

Big Easy Painters Releases Detailed Guide on Selecting the Right Paint for Kitchen Cabinets

NEW ORLEANS, LA – March 17, 2026 – PRESSADVANTAGE – For homeowners weighing whether to replace or repaint kitchen

March 17, 2026

Muse Treatment Alcohol & Drug Rehab Los Angeles Publishes Critical New Resource on Website Examining Withdrawal Treatment for Xylazine-Linked “Zombie Drug” Exposure

Muse Treatment Alcohol & Drug Rehab Los Angeles Publishes Critical New Resource on Website Examining Withdrawal Treatment for Xylazine-Linked “Zombie Drug” Exposure

LOS ANGELES, CA – March 17, 2026 – PRESSADVANTAGE – Muse Treatment Alcohol & Drug Rehab Los Angeles has released a

March 17, 2026

SERVPRO of Downtown Minneapolis Shares Frozen Pipe Prevention Tips

SERVPRO of Downtown Minneapolis Shares Frozen Pipe Prevention Tips

March 17, 2026 – PRESSADVANTAGE – SERVPRO of Downtown Minneapolis has released guidance to help property owners protect

March 17, 2026

Bloomingdale School of Music Announces Patrice Jean as Board President; Honoring of Outgoing President Ken Michaels

Bloomingdale School of Music Announces Patrice Jean as Board President; Honoring of Outgoing President Ken Michaels

Bloomingdale School of Music Announces Patrice Jean as Board President; Honoring the Multi-Generational Legacy of

March 17, 2026

Friends of Commerce Launches ‘Friends of AI’ and Expands Into AI Enterprise Consulting

Friends of Commerce Launches ‘Friends of AI’ and Expands Into AI Enterprise Consulting

Friends of Commerce launches Friends of AI, a new division delivering secure, flexible, and ROI-driven AI consulting

March 17, 2026

3V3i Completes EV Supercharging Site in Record 5 Business Days, Accelerating Charging Infrastructure Deployment

3V3i Completes EV Supercharging Site in Record 5 Business Days, Accelerating Charging Infrastructure Deployment

Prefab manufacturing and integrated design process cut industry deployment timelines in half at new IONNA site in

March 17, 2026

Jason Ruedy Says Estes Park Investors Are Using DSCR Loans to Consolidate Debt

Jason Ruedy Says Estes Park Investors Are Using DSCR Loans to Consolidate Debt

Estes Park Mortgage Expert Jason Ruedy “The Home Loan Arranger” Says Real Estate Investors Are Using DSCR Loans to

March 17, 2026

Nonprofit Leaders Use AI to Find Funding at March 31 Summit

Nonprofit Leaders Use AI to Find Funding at March 31 Summit

Panel moderated by KTLA’s Sandra Mitchell will bring together nonprofit, civic and business leaders from across the

March 17, 2026

Minx Law Attorneys Charlene Minx and Andrea Cristiani Earn 2026 Super Lawyers Distinctions

Minx Law Attorneys Charlene Minx and Andrea Cristiani Earn 2026 Super Lawyers Distinctions

Minx Law celebrates 2026 Super Lawyers recognition for Founder & Principal Charlene Minx and Attorney Andrea

March 17, 2026

Rossario George Dominates Awards Season with Appearances at the Grammys, Golden Globes, and Oscars

Rossario George Dominates Awards Season with Appearances at the Grammys, Golden Globes, and Oscars

To see these powerful women step onto global stages wearing Rossario George is both humbling and energizing.”— Tony

March 17, 2026

Kaiserpunk Celebrates One-Year Anniversary With Free Game Update

Kaiserpunk Celebrates One-Year Anniversary With Free Game Update

After a year of improvements and eight major updates since launch, the grand city builder expands with monuments,

March 17, 2026