This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

EON Resources Inc. Announces Its 2026 Drilling Program Commencing with Recompletion of 5 Wells in the San Andres, and 3 of 92 New San Andres Horizontal Wells

EON Resources Inc. Announces Its 2026 Drilling Program Commencing with Recompletion of 5 Wells in the San Andres, and 3 of 92 New San Andres Horizontal Wells

HOUSTON, TX / ACCESS Newswire / March 19, 2026 / EON Resources Inc. (NYSE American:EONR) ("EON" or the "Company") is an

March 19, 2026

Dateline Secures Second Rig to Fast-Track Colosseum REE Program

Dateline Secures Second Rig to Fast-Track Colosseum REE Program

SAN BERNARDINO, CA / ACCESS Newswire / March 19, 2026 / Dateline Resources Limited (ASX:DTR)(OTCQB:DTREF)(FSE:YE1)

March 19, 2026

New to The Street Renews 12-Part Media Series with Roadzen, Inc. (NASDAQ: RDZN)

New to The Street Renews 12-Part Media Series with Roadzen, Inc. (NASDAQ: RDZN)

Integrated Campaign to Include National Broadcast Interviews, Times Square Billboards, Earned Media, NewsOut PR

March 19, 2026

Aspire Biopharma’s Subsidiary Announces Agreement with TruLife Distribution to Drive National Retail Expansion

Aspire Biopharma’s Subsidiary Announces Agreement with TruLife Distribution to Drive National Retail Expansion

Agreement Set to Expand BUZZ BOMB™ Distribution Across Natural, Specialty, and Mass Merchandiser Channels ESTERO, FL /

March 19, 2026

Wellgistics Management Converts $2 Million in Deferred Compensation into Equity at $0.20 per Share

Wellgistics Management Converts $2 Million in Deferred Compensation into Equity at $0.20 per Share

TAMPA, FL / ACCESS Newswire / March 19, 2026 / Wellgistics Health, Inc. (NASDAQ:WGRX) ("Wellgistics"), a health

March 19, 2026

Worksport Presents New Premium “Game Changer” Tonneau Cover Model to Industry Buyers at Keystone BIG Show; Initiates Pre-Orders Ahead of Near-Term Commercial Launch

Worksport Presents New Premium “Game Changer” Tonneau Cover Model to Industry Buyers at Keystone BIG Show; Initiates Pre-Orders Ahead of Near-Term Commercial Launch

New Model Presented to North America's leading automotive aftermarket distributor targets major expansion of U.S.

March 19, 2026

ACCESS Newswire Reports Fourth Quarter and Full Year 2025 Results

ACCESS Newswire Reports Fourth Quarter and Full Year 2025 Results

Increased ARR Leads to Higher Gross Margins and Adjusted EBITDAQ4 2025 revenue grew modestly to $5.8M compared to $5.7M

March 19, 2026

SMX Powers The New Materials Economy As Energy Costs Redefine Global Supply Chains

SMX Powers The New Materials Economy As Energy Costs Redefine Global Supply Chains

NEW YORK, NY / ACCESS Newswire / March 19, 2026 / SMX (Security Matters) PLC (NASDAQ:SMX; SMXWW) is redefining material

March 19, 2026

TuxCare Announces Strategic Expansion of its CVE Tracker for End-of-Life Open-Source Software

TuxCare Announces Strategic Expansion of its CVE Tracker for End-of-Life Open-Source Software

PALO ALTO, CA, UNITED STATES, March 19, 2026 /EINPresswire.com/ — TuxCare, a global innovator in securing open source,

March 19, 2026

Influential Women Profiles Lindsey Martinez-Carey: Team Lead And Revenue Cycle Customer Service Specialist

Influential Women Profiles Lindsey Martinez-Carey: Team Lead And Revenue Cycle Customer Service Specialist

CHARLOTTE, NC, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Enhancing the Patient Experience Through Education,

March 19, 2026

Influential Women Profiles Jasmine L. Miller-Dixon, MPP, MS: Business Development And Capture Strategist

Influential Women Profiles Jasmine L. Miller-Dixon, MPP, MS: Business Development And Capture Strategist

WASHINGTON, DC, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Advancing Strategic Initiatives and Driving Growth

March 19, 2026

Enterprises Are Flying Blind on AI – InnerActiv Closes the Endpoint Visibility Gap

Enterprises Are Flying Blind on AI – InnerActiv Closes the Endpoint Visibility Gap

New platform defines endpoint-based AI governance, giving organizations real-time control, guidance, and visibility

March 19, 2026

Southern Forest Heritage Museum Invites Louisiana Families to Rediscover a Hidden Historic Gem

Southern Forest Heritage Museum Invites Louisiana Families to Rediscover a Hidden Historic Gem

Central Louisiana destination features historic trains, immersive exhibits, and outdoor exploration perfect for spring

March 19, 2026

With Doctor Waits Averaging 31 Days, Vosita Aims to Close the Gap

With Doctor Waits Averaging 31 Days, Vosita Aims to Close the Gap

New feature lets patients request appointments even when calendars appear full, helping practices capture demand that

March 19, 2026

Michigan Financial Educators Council Selects Krystena Yancey to Join Its Advisory Board

Michigan Financial Educators Council Selects Krystena Yancey to Join Its Advisory Board

Krystena Yancey’s work helping individuals build wealth in ways that reflect their personalities and goals brings an

March 19, 2026

Know Your Worth Hosts Their First-Ever Philly Muslim Girls Empowerment Day

Know Your Worth Hosts Their First-Ever Philly Muslim Girls Empowerment Day

Philly Muslim Girls Empowerment Day to be held on April 5, 2026 at Temple University, will uplift Muslim girls through

March 19, 2026

Keeper Security Introduces KeeperDB™, Integrating Zero-Trust Database Access into KeeperPAM®

Keeper Security Introduces KeeperDB™, Integrating Zero-Trust Database Access into KeeperPAM®

LONDON, UNITED KINGDOM, March 19, 2026 /EINPresswire.com/ — New capability embeds a secure, zero-trust database

March 19, 2026

India’s Travel Industry Enters a New Era

India’s Travel Industry Enters a New Era

Faresefursat.com Launches First-Ever Voice AI Booking System NAVI MUMBAI, MAHARASHTRA, INDIA, March 19, 2026

March 19, 2026

Influential Women Recognizes Kristina Klos for Driving Strategic Marketing Innovation Across the Automotive Industry

Influential Women Recognizes Kristina Klos for Driving Strategic Marketing Innovation Across the Automotive Industry

ALLEN PARK, MI, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Senior Marketing Leader, Kristina Klos, Recognized

March 19, 2026

Toss the Coin Rebrands ThoughtFocus as a Domain-Driven, AI-Led Innovation Partner

Toss the Coin Rebrands ThoughtFocus as a Domain-Driven, AI-Led Innovation Partner

MA, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Toss the Coin Ltd., a premier B2B brand and marketing strategy

March 19, 2026

Smart City Expo Miami Announces Global Conference on Urban Intelligence and Regenerative Cities

Smart City Expo Miami Announces Global Conference on Urban Intelligence and Regenerative Cities

Premier Event Brings Together World Leaders to Showcase Real-World Case Studies on Regenerative Urban Futures Smart

March 19, 2026

2025 Outcomes Report Shows Foundation Stone Wellness Mental Health Model Driving Measurable Gains Across Key Indicators

2025 Outcomes Report Shows Foundation Stone Wellness Mental Health Model Driving Measurable Gains Across Key Indicators

Foundation Stone Wellness reports major gains in recovery, resilience, and symptom reduction, highlighting a new

March 19, 2026

Algo Reaffirms Strategic Commitment to NetSuite Community with Significant Investment in Native Intuiflow Solution

Algo Reaffirms Strategic Commitment to NetSuite Community with Significant Investment in Native Intuiflow Solution

Intuiflow for NetSuite gives NetSuite planners the confidence to build better, more resilient plans, without ever

March 19, 2026

BLUE HAWK Names Unilog an Alliance Partner for HVACR Content and eCommerce

BLUE HAWK Names Unilog an Alliance Partner for HVACR Content and eCommerce

Unilog’s HVACR Growth Program gives BLUE HAWK members access to enriched product content and flexible eCommerce

March 19, 2026

LIV Sotheby’s International Realty Announces Record-Breaking Sale in Crested Butte

LIV Sotheby’s International Realty Announces Record-Breaking Sale in Crested Butte

Skyland Home Boasts 360-Degree Mountain Views, Access to National Forest Land, and 1,000-Bottle Wine Cellar CRESTED

March 19, 2026

TD2 Announces Publication of Phase II Ketogenic Diet Trial Showing Improved Survival in Metastatic Pancreatic Cancer

TD2 Announces Publication of Phase II Ketogenic Diet Trial Showing Improved Survival in Metastatic Pancreatic Cancer

Company Served as Sponsor and Provided Operational Leadership for Study Conducted in Partnership with TGen and Virta

March 19, 2026

PropertyRoom.com Presents a Hermes Birkin Handbag for Public Auction

PropertyRoom.com Presents a Hermes Birkin Handbag for Public Auction

We often get luxury handbags and other designer fashion pieces to auction, but this Birkin Handbag is an incredibly

March 19, 2026

Ottimate Appoints Shawn Lane as CEO to Lead Next Phase of AI-Driven Growth

Ottimate Appoints Shawn Lane as CEO to Lead Next Phase of AI-Driven Growth

Former LivTech CEO to scale Ottimate’s AI-powered finance platform. SAN FRANCISCO, CA, UNITED STATES, March 19, 2026

March 19, 2026

ETR’s 2026 Annual State of Security report finds AI security overtaking cloud as top enterprise priority

ETR’s 2026 Annual State of Security report finds AI security overtaking cloud as top enterprise priority

New survey of 517 security leaders shows rapid rise of AI security spending, increasing focus on identity, and a shift

March 19, 2026

Etherio Earns Three GDUSA Design Awards Across Corporate, Association, and Life Sciences Work

Etherio Earns Three GDUSA Design Awards Across Corporate, Association, and Life Sciences Work

Award-winning creative spans three divisions and highlights Etherio’s ability to translate strategy into high-impact

March 19, 2026

Genuin Launches Monetize: New Sponsored Access Formats Give Brands and Media Companies Direct Path to New Revenue

Genuin Launches Monetize: New Sponsored Access Formats Give Brands and Media Companies Direct Path to New Revenue

Publishers are already deploying Monetize, activating upfront sponsored placements across owned properties, extending

March 19, 2026

Cubicle Fugitive co-founder Morgan MacLeod elected to 2026–27 international board of Legal Marketing Association

Cubicle Fugitive co-founder Morgan MacLeod elected to 2026–27 international board of Legal Marketing Association

Morgan MacLeod, co-founder of Cubicle Fugitive, elected to the LMA international board as Member at Large for a

March 19, 2026

Quasi Robotics Launches New Model C2 Deployment & Integration Services

Quasi Robotics Launches New Model C2 Deployment & Integration Services

Expert support to accelerate autonomous robot rollouts, maximize safety, and scale intelligent automation across

March 19, 2026

Consuelo Vanderbilt Costin Global Mentorship Initiative to Empower B. Wright Leadership Academy’s Next Generation

Consuelo Vanderbilt Costin Global Mentorship Initiative to Empower B. Wright Leadership Academy’s Next Generation

NEW YORK, NY, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Consuelo Vanderbilt Costin brought her SohoMuse

March 19, 2026

Audivi and Quail Digital Launch Zero-Cost Voice AI Hardware Program for Drive-Thru Operators

Audivi and Quail Digital Launch Zero-Cost Voice AI Hardware Program for Drive-Thru Operators

New program enables drive-thru automation across 32 countries with no upfront hardware cost for Voice AI deployment.

March 19, 2026

World Breathing Day 2026: ‘Pause, Breathe, Unite’

World Breathing Day 2026: ‘Pause, Breathe, Unite’

World Breathing Day 2026: “Pause, Breathe, Unite” — A Worldwide Invitation to Empower Breathing & Unity on Earth on

March 19, 2026

LangGuard.AI Unveils an Open AI Control Plane to Accelerate Enterprise Agentic ROI

LangGuard.AI Unveils an Open AI Control Plane to Accelerate Enterprise Agentic ROI

Proactively manage and operate multi-agent workflow and tools actions in run-time The IT department of every company is

March 19, 2026

Branford Group Announces Two-Day Lumileds Semiconductor Auction

Branford Group Announces Two-Day Lumileds Semiconductor Auction

Two-day online auction of 3,000+ Lumileds semiconductor assets in San Jose, featuring advanced fab, R&D, and

March 19, 2026

Michigan Homeowners Face Escalating Basement Flooding, Foundation Leaks, and Drainage Issues

Michigan Homeowners Face Escalating Basement Flooding, Foundation Leaks, and Drainage Issues

Michigan Homeowners Face Escalating Basement Flooding, Foundation Leaks, and Drainage Issues Urgent Need for

March 19, 2026

Influential Women Features Rayda L. Menendez: Founder Of Prime Permitting & Consulting And Prime Online Notary Services

Influential Women Features Rayda L. Menendez: Founder Of Prime Permitting & Consulting And Prime Online Notary Services

POMPANO BEACH, FL, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Construction Permitting Specialist with 20+

March 19, 2026