This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Cambre & Associates Expands Legal Representation for Rideshare Accident Victims Across Greater Atlanta

Cambre & Associates Expands Legal Representation for Rideshare Accident Victims Across Greater Atlanta

Atlanta personal injury firm intensifies focus on Uber and Lyft accident claims as rideshare-related injuries continue

March 19, 2026

InventionHome® Inventor Creates Portable Electric Pill Grinder to Improve Medication Administration and Dosage Accuracy

InventionHome® Inventor Creates Portable Electric Pill Grinder to Improve Medication Administration and Dosage Accuracy

PITTSBURGH, PA, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Paul Gregory of Exeter, U.K. is the creator of the

March 19, 2026

Scar Formation Begins Almost Immediately After Surgery, Experts Say

Scar Formation Begins Almost Immediately After Surgery, Experts Say

Recovery specialists emphasize that early scar development plays a critical role in long-term mobility, comfort, and

March 19, 2026

SUDEN PR CELEBRATES SOUTH FLORIDA GROWTH WITH OFFICIAL RIBBON CUTTING IN PALM BEACH COUNTY

SUDEN PR CELEBRATES SOUTH FLORIDA GROWTH WITH OFFICIAL RIBBON CUTTING IN PALM BEACH COUNTY

The boutique PR agency marks continued growth with celebration of community and client success Palm Beach County has

March 19, 2026

Flying Squirrel Launches ‘March Break Movement Challenge’ to Keep Kids Active During School Holidays

Flying Squirrel Launches ‘March Break Movement Challenge’ to Keep Kids Active During School Holidays

COEUR D'ALENE, ID, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Flying Squirrel Sports is inviting families

March 19, 2026

OFFMARKET24 Crosses 18,000 Verified Investor Mark as Off-Market Real Estate Gains Momentum in Germany

OFFMARKET24 Crosses 18,000 Verified Investor Mark as Off-Market Real Estate Gains Momentum in Germany

US-based PropTech company connects property sellers with qualified buyers through AI-driven matching across 500,000+

March 19, 2026

PETVIVO HOLDINGS, INC. TO EXHIBIT AT THE ACVSMR SYMPOSIUM IN LEXINGTON, KENTUCKY

PETVIVO HOLDINGS, INC. TO EXHIBIT AT THE ACVSMR SYMPOSIUM IN LEXINGTON, KENTUCKY

PetVivo Holdings, Inc. (OTCQX:PETV, PETVW)MINNEAPOLIS, MN, UNITED STATES, March 19, 2026 /EINPresswire.com/ — PetVivo

March 19, 2026

Lionstone Healthcare Partners with Clasp to Open New Career Pathways for Healthcare Workers — From Frontlines to Bedside

Lionstone Healthcare Partners with Clasp to Open New Career Pathways for Healthcare Workers — From Frontlines to Bedside

The initiative offers student loan repayment to nursing & therapy graduates and to current employees, including

March 19, 2026

HEIPI Expands Camera Support Line with Compact Tools for Travel, Wildlife and Hybrid Content Creation

HEIPI Expands Camera Support Line with Compact Tools for Travel, Wildlife and Hybrid Content Creation

NEW YORK, NY, UNITED STATES, March 19, 2026 /EINPresswire.com/ — HEIPI TECHNOLOGY LIMITED is pleased to announce the

March 19, 2026

Fen X Custom Releases New Setup Guide to Enhance User Onboarding

Fen X Custom Releases New Setup Guide to Enhance User Onboarding

GRAWN, MI, UNITED STATES, March 19, 2026 /EINPresswire.com/ — In this high-tech society, sometimes things are not as

March 19, 2026

Absolute Capital Management’s Teberg Fund Wins Two 2026 LSEG Lipper Fund Awards

Absolute Capital Management’s Teberg Fund Wins Two 2026 LSEG Lipper Fund Awards

Teberg Fund is a LSEG Lipper Fund Awards 2026 USA Winner: Best Fund in the Flexible Portfolio Funds category for 3-

March 19, 2026

NoFraud Rebrands as Wyllo, Introducing a CX-First Approach to Ecommerce Risk Intelligence

NoFraud Rebrands as Wyllo, Introducing a CX-First Approach to Ecommerce Risk Intelligence

Wyllo brings together NoFraud’s payment fraud prevention and Yofi’s post-purchase risk intelligence into a unified

March 19, 2026

Songstress Yvette Michele Returns To The Music Scene With The Dance Hit, ‘Mr. DJ’

Songstress Yvette Michele Returns To The Music Scene With The Dance Hit, ‘Mr. DJ’

Collaboration with DJ/remixer FENN resulting in over a million streams online NEW YORK, NY, UNITED STATES, March 19,

March 19, 2026

Stryker, THINK Surgical and Carlsmed Named Winners of 2026 OMTEC® Excellence Awards

Stryker, THINK Surgical and Carlsmed Named Winners of 2026 OMTEC® Excellence Awards

The 2026 OMTEC Excellence Awards highlight innovations advancing joint replacement, robotics and personalized spine

March 19, 2026

2026 Small Business Blueprint: AI Citations, Agentic AI & Hyper-Local Third Spaces Drive 10X Growth. MyTSV.COM News

2026 Small Business Blueprint: AI Citations, Agentic AI & Hyper-Local Third Spaces Drive 10X Growth. MyTSV.COM News

Game-Changing Guide for SMBs to Replace SEO with AI Visibility, Scale with Tiny Teams, Micro-Shore Supplies & Build

March 19, 2026

Temple of the Arts to Present ‘Shared Heritage of Freedom’ Shabbat Service on Friday, March 27 at the Saban Theatre

Temple of the Arts to Present ‘Shared Heritage of Freedom’ Shabbat Service on Friday, March 27 at the Saban Theatre

Special Shabbat gathering will honor the shared heritage of freedom between Jewish and African American communities

March 19, 2026

AMAG Technology Receives Growth Investment from Security-Focused Investor Egis Capital

AMAG Technology Receives Growth Investment from Security-Focused Investor Egis Capital

Egis’ growth capital supports AMAG’s commitment to serving high-security environments and investing in advanced

March 19, 2026

UMusic Hospitality & Lifestyle Engages David Kuperberg to Lead North American Expansion

UMusic Hospitality & Lifestyle Engages David Kuperberg to Lead North American Expansion

MIAMI, FL, UNITED STATES, March 19, 2026 /EINPresswire.com/ — UMusic Hospitality & Lifestyle today announced the

March 19, 2026

Opera GX Gaming Browser Lands on Linux After Community Demand

Opera GX Gaming Browser Lands on Linux After Community Demand

Linux Users Gain a Browser That Optimizes Performance for Gaming and Gives Them Control Over The Resources They Use

March 19, 2026

Eastin Thana City Golf Resort Bangkok Achieves Prestigious Green Globe Certification

Eastin Thana City Golf Resort Bangkok Achieves Prestigious Green Globe Certification

Eastin Thana City Golf Resort Bangkok has achieved Green Globe certification, marking a significant milestone in the

March 19, 2026

Emilia Vaughn Supports Nour Khodr at Teragram Ballroom in Los Angeles

Emilia Vaughn Supports Nour Khodr at Teragram Ballroom in Los Angeles

Emilia Vaughn returns to the stage with an intimate LA set, supporting Nour Khodr as he launches his debut North

March 19, 2026

Former FS-ISAC CEO Steven Silberstein Joins CYBERA as Strategic Advisor

Former FS-ISAC CEO Steven Silberstein Joins CYBERA as Strategic Advisor

AI-Powered Mule Intelligence Company Gains Leader with Deep Financial Services Expertise Traditional controls struggle

March 19, 2026

Arden Courts Northern New Jersey to Host Power of the Mind Alzheimer’s & Dementia Conference

Arden Courts Northern New Jersey to Host Power of the Mind Alzheimer’s & Dementia Conference

Free educational event brings together clinical experts, resources, and community support for those navigating memory

March 19, 2026

Gourmet Modern Café Toastique to Open April 11 in Westlake Village

Gourmet Modern Café Toastique to Open April 11 in Westlake Village

Toastique will Serve a Nutritious, All-Day Menu at the New Location WESTLAKE VILLAGE, CA, UNITED STATES, March 19, 2026

March 19, 2026

Secufusion Introduces Unified AI Detection & Response (AIDR) to Secure AI Copilots, Agents, and Browser Workflows

Secufusion Introduces Unified AI Detection & Response (AIDR) to Secure AI Copilots, Agents, and Browser Workflows

A new security layer built for the AI‑powered workspace—protecting copilots, agents, and browser‑based work in real

March 19, 2026

Digital Accelerant Introduces Executive Impact Generator™ to Turn QR Code Scans Into Lead Magnets

Digital Accelerant Introduces Executive Impact Generator™ to Turn QR Code Scans Into Lead Magnets

New AI-powered feature gives professionals a compelling reason to scan their Video Business Cards™ by instantly

March 19, 2026

SBS Taps Adam Shpiro as Chief Marketing Officer to Lead Global Brand Expansion

SBS Taps Adam Shpiro as Chief Marketing Officer to Lead Global Brand Expansion

Former JPMorgan Exec to Oversee Global Brand as SBS Brings AI Capabilities to Banks and Financial Firms Across Europe,

March 19, 2026

Woolly Bear Capital Announces Final Close of Cherry Fund II

Woolly Bear Capital Announces Final Close of Cherry Fund II

Cherry Fund II closed in November 2025 following a speedy fundraise, with 5x growth from Fund I, a 10x increase in LPs,

March 19, 2026

ClawSecure Outranks Google on Product Hunt as Demand for OpenClaw Security Surges

ClawSecure Outranks Google on Product Hunt as Demand for OpenClaw Security Surges

ClawSecure reached #2 Product of the Day with 1,498 users scanning OpenClaw agents in 24 hours, outranking Google

March 19, 2026

Parcel Volumes Set to Rise 20-25%, but Profitability, Not Growth, Will Define Shipping Leaders in 2026

Parcel Volumes Set to Rise 20-25%, but Profitability, Not Growth, Will Define Shipping Leaders in 2026

As parcel volumes rise, carriers prioritize profitability, forcing shippers to rethink cost-to-serve, pricing strategy,

March 19, 2026

The Advocacy Circle Highlights a Structured Process for Addressing School Accommodation Concerns

The Advocacy Circle Highlights a Structured Process for Addressing School Accommodation Concerns

When complaints feel pointless, TAC gives parents a structured escalation ladder to restore access and accountability.

March 19, 2026

Virginia 811 Launches Mobile Learning Center to Teach Kids Safe Digging

Virginia 811 Launches Mobile Learning Center to Teach Kids Safe Digging

New mobile unit delivers hands-on 811 safety education to children at schools and community events across Virginia. The

March 19, 2026

Elite Strategic Solutions Celebrates Internal Promotion, Showcasing Pathways for Career Growth

Elite Strategic Solutions Celebrates Internal Promotion, Showcasing Pathways for Career Growth

Elite Strategic Solutions celebrates Christian Esposito’s promotion, demonstrating his career growth and leadership

March 19, 2026

Influential Women Showcases Lexie Watts: Marketing Manager And Events Planner, Elevating Brand Experiences

Influential Women Showcases Lexie Watts: Marketing Manager And Events Planner, Elevating Brand Experiences

HOOVER, AL, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Blending Creativity, Strategy, and Community Engagement

March 19, 2026

Salita Jones, Recognized By Influential Women, Director Of Education & Events At TRSA Driving Innovation

Salita Jones, Recognized By Influential Women, Director Of Education & Events At TRSA Driving Innovation

ALEXANDRIA, VA, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Leading Seamless Conferences, Training Programs,

March 19, 2026

Team One Insurance Services Partners with Adjusto to Modernize Contents Claims Handling for Adjusters and Carriers

Team One Insurance Services Partners with Adjusto to Modernize Contents Claims Handling for Adjusters and Carriers

The collaboration brings AI-powered contents valuation and workflow clarity to one of the most manual aspects of

March 19, 2026

NEVER-BEFORE-SEEN STAR WARS SET PHOTOGRAPHS TO BE OFFERED AT PROPSTORE AUCTION

NEVER-BEFORE-SEEN STAR WARS SET PHOTOGRAPHS TO BE OFFERED AT PROPSTORE AUCTION

Stuart Ziff’s photographs go beyond the finished film, capturing the people, the process, and the atmosphere on set.”—

March 19, 2026

The North South Chamber Orchestra Celebrates the Arrival of Spring on Tuesday, March 24 @ 7 PM

The North South Chamber Orchestra Celebrates the Arrival of Spring on Tuesday, March 24 @ 7 PM

The program features enchanting revivals of three brilliant works by composers Daniel Kessner, Max Lifchitz, and Robert

March 19, 2026

AuraLift Ai Announces Clinical Advisory Board of Board-Certified Psychiatrists and Psychologists

AuraLift Ai Announces Clinical Advisory Board of Board-Certified Psychiatrists and Psychologists

New advisory board brings board-certified psychiatrists and licensed clinical psychologists to guide AI coaching

March 19, 2026

Hairmax® to Present 25 Years of FDA-Cleared Laser Hair Growth Innovation at AAD 2026

Hairmax® to Present 25 Years of FDA-Cleared Laser Hair Growth Innovation at AAD 2026

With eight FDA clearances and seven clinical studies, Hairmax defines the gold standard in laser hair regrowth

March 19, 2026