This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Atlanta Auto Law Launches New Website to Enhance Legal Services for Motor Vehicle Accident Victims

Atlanta Auto Law Launches New Website to Enhance Legal Services for Motor Vehicle Accident Victims

ATLANTA, GA – March 19, 2026 – PRESSADVANTAGE – Atlanta Auto Law has launched a new website designed to provide focused

March 19, 2026

Michelle’s Adoorable Creations Will Open Preorders for 2026 Homecoming Mums, Garters, and Game Day Items on June 1, 2026

Michelle’s Adoorable Creations Will Open Preorders for 2026 Homecoming Mums, Garters, and Game Day Items on June 1, 2026

March 19, 2026 – PRESSADVANTAGE – Michelle’s Adoorable Creations announced that preorders for 2026 homecoming mums,

March 19, 2026

Invisible Braces Kidbrooke Teeth Straightening Dentist Dr Mori Shahid Advises Invisalign Consultations at Kidbrooke Village Dentist (Smile 4 U)

Invisible Braces Kidbrooke Teeth Straightening Dentist Dr Mori Shahid Advises Invisalign Consultations at Kidbrooke Village Dentist (Smile 4 U)

London, England – March 19, 2026 – PRESSADVANTAGE – Kidbrooke Village Dentist (Smile 4 U) has announced the

March 19, 2026

Ginza Diamond Shiraishi Hong Kong Highlights Craftsmanship, Design, and Material Standards in Wedding Ring Collections

Ginza Diamond Shiraishi Hong Kong Highlights Craftsmanship, Design, and Material Standards in Wedding Ring Collections

HONG KONG, HK – March 19, 2026 – PRESSADVANTAGE – Ginza Diamond Shiraishi Hong Kong has issued an official statement

March 19, 2026

Big Easy Patio Marks 30 Years of Patio Construction with Expanded Outdoor Living Services

Big Easy Patio Marks 30 Years of Patio Construction with Expanded Outdoor Living Services

NEW ORLEANS, LA – March 19, 2026 – PRESSADVANTAGE – Big Easy Patio, a patio design and construction company, has

March 19, 2026

partnrUP Named Easiest Influencer Marketing Platform to Use in G2 Spring 2026 Reports Across SMB and Enterprise

partnrUP Named Easiest Influencer Marketing Platform to Use in G2 Spring 2026 Reports Across SMB and Enterprise

AI-powered creator platform earns 17th consecutive quarter as a High Performer, recognized for usability, performance,

March 19, 2026

Private Jet Card Comparisons launches PJCC for Corporate Flight Departments

Private Jet Card Comparisons launches PJCC for Corporate Flight Departments

Corporate flight departments and companies that use business aviation now have access to updated third-party data to

March 19, 2026

Postland LLC Launches Parcel Consolidation Services for Businesses Operating Between the U.S. and Europe

Postland LLC Launches Parcel Consolidation Services for Businesses Operating Between the U.S. and Europe

Memphis-based logistics company enters the market with an integrated platform designed to simplify cross-border

March 19, 2026

Staatsolie to Chart Suriname’s Offshore Future at Caribbean Energy Week 2026

Staatsolie to Chart Suriname’s Offshore Future at Caribbean Energy Week 2026

The national oil company will showcase its role in shaping offshore investment opportunities, recent exploration

March 19, 2026

DOXA® Talent Recognized as a Philippines Best Workplace™ 2026 by Great Place To Work®

DOXA® Talent Recognized as a Philippines Best Workplace™ 2026 by Great Place To Work®

DOXA Talent is recognized as one of the Philippines Best Workplaces™ 2026, honoring its people‑first culture and

March 19, 2026

Troya Mediterranean Wins Marin Independent Journal Readers’ Choice Award 2026 for Best Mediterranean

Troya Mediterranean Wins Marin Independent Journal Readers’ Choice Award 2026 for Best Mediterranean

Marin Community Recognizes Troya Mediterranean in 10th Anniversary Edition This award is incredibly meaningful to us

March 19, 2026

HonestWaves Accelerates Growth With New Enterprise, Public Sector, and Community Partnerships

HonestWaves Accelerates Growth With New Enterprise, Public Sector, and Community Partnerships

Momentum Driven by Expanded Client Roster Including Toyota, Ohio State University, and Hilton SIGNAL HILL, CA, UNITED

March 19, 2026

ARH Consulting Expands Real Estate Strategy Advisory for Family Offices and Wealth Management Firms

ARH Consulting Expands Real Estate Strategy Advisory for Family Offices and Wealth Management Firms

Advisory platform helps integrate real estate into institutional-grade wealth management frameworks for high-net-worth

March 19, 2026

Washington’s National Park Fund Awards Record $2.28M in Grants to Mount Rainier, North Cascades, Olympic National Parks

Washington’s National Park Fund Awards Record $2.28M in Grants to Mount Rainier, North Cascades, Olympic National Parks

Funding supporting 40+ projects across Washington’s national parks, addressing urgent needs today and investing in

March 19, 2026

2025 Exposed a New Reality for Drivers as Defects and Tech Issues Shape Lemon Law in 2026

2025 Exposed a New Reality for Drivers as Defects and Tech Issues Shape Lemon Law in 2026

New 2025 data reveals rising vehicle defects, increased software failures, and lower driver satisfaction, reshaping how

March 19, 2026

Golden State Film Festival Outlines Weeklong Program at TCL Chinese 6 Theatres

Golden State Film Festival Outlines Weeklong Program at TCL Chinese 6 Theatres

Golden State Film Festival Hosts Filmmakers at TCL Chinese 6 Theatres in Hollywood, CA HOLLYWOOD, CA, UNITED STATES,

March 19, 2026

Alite Laser Set to Unveil Highly Anticipated Mueller Location with Landmark Grand Opening Event

Alite Laser Set to Unveil Highly Anticipated Mueller Location with Landmark Grand Opening Event

Austin’s legacy medical spa expands its footprint to the Simond Avenue corridor, offering exclusive inaugural rewards

March 19, 2026

Far Reach Ranch U-Pick Blueberry Season Returns Easter Weekend

Far Reach Ranch U-Pick Blueberry Season Returns Easter Weekend

Fourth-generation Tavares farm offers berry picking, special events, + family fun beginning April 4 We love welcoming

March 19, 2026

ON THE KNOWS with Randall Kenneth Jones Joins C-Suite Radio, Expanding Reach to Global Executive & Leadership Audiences

ON THE KNOWS with Randall Kenneth Jones Joins C-Suite Radio, Expanding Reach to Global Executive & Leadership Audiences

Environmental activist Erin Brockovich has enthusiastically endorsed the podcast, praising the show and its host as

March 19, 2026

Secuvy Names Ed Lingo Vice President of Engineering as Enterprises Race to Deploy AI at Scale

Secuvy Names Ed Lingo Vice President of Engineering as Enterprises Race to Deploy AI at Scale

New engineering leader accelerates Secuvy's mission to solve the hardest data challenges enterprises face before their

March 19, 2026

Nature Survey Reveals Natural Surroundings as Key Driver for Superior Event Experiences at Houston’s City Place

Nature Survey Reveals Natural Surroundings as Key Driver for Superior Event Experiences at Houston’s City Place

Survey of event planners highlights the Houston hub’s 150-acre nature preserve and sustainable infrastructure as top

March 19, 2026

96% of Women Still Undergo Fibroid Surgery Despite Availability of Non-Surgical Alternatives, New Reports Show

96% of Women Still Undergo Fibroid Surgery Despite Availability of Non-Surgical Alternatives, New Reports Show

USA Fibroid Centers marks one year of landmark research confirming outpatient UFE improves quality of life for 86% of

March 19, 2026

Gene Altman’s New Collection ‘The Road Home and Other Stories’ Explores the Depths of the Human Heart

Gene Altman’s New Collection ‘The Road Home and Other Stories’ Explores the Depths of the Human Heart

Psychiatrist-Turned-Author Unveils Gripping Short Fiction Packed with Emotion, Insight, and Vivid Imagery NY, UNITED

March 19, 2026

Knecht Cup Regatta to Honor Mark Valenti with Men’s Frosh/Novice Four Trophy

Knecht Cup Regatta to Honor Mark Valenti with Men’s Frosh/Novice Four Trophy

Veteran coach, mentor and regatta leader has devoted more than 60 years to Philadelphia rowing. Mark Valenti represents

March 19, 2026

Teti Becomes the First AI Assistant in the World That Actively Protects Your Brain

Teti Becomes the First AI Assistant in the World That Actively Protects Your Brain

TetiAI releases Lucid — the first open-source cognitive protection system for AI, built on 30+ peer-reviewed studies,

March 19, 2026

Patriot Select Completes Profitable Inaugural Year; Reinvests Gains for Florida Market Stability

Patriot Select Completes Profitable Inaugural Year; Reinvests Gains for Florida Market Stability

ST. PETERSBURG , FL, UNITED STATES, March 19, 2026 /EINPresswire.com/ — Patriot Select Property and Casualty Insurance

March 19, 2026

Wake United Surf + Wake Series Sets 2026 Schedule, Returns With Four Stops Across Florida and Georgia

Wake United Surf + Wake Series Sets 2026 Schedule, Returns With Four Stops Across Florida and Georgia

Two-Time Nautique Dealer Event of the Year Series Opens Season With Nautique WWA Florida State Championships and

March 19, 2026

ShipMonk Opens First Fulfillment Center Designed Specifically for Apparel Brands

ShipMonk Opens First Fulfillment Center Designed Specifically for Apparel Brands

New Louisville facility reflects ShipMonk's continued focus on apparel brands, with fulfillment tailored to the unique

March 19, 2026

Vital Wellness Center Emphasizes Data-Driven, Neurologically Focused Family Chiropractic Care in Kane County, IL Since 2002

Vital Wellness Center Emphasizes Data-Driven, Neurologically Focused Family Chiropractic Care in Kane County, IL Since 2002

ELBURN, IL – March 19, 2026 – PRESSADVANTAGE – Vital Wellness Center has emphasized its commitment to a data-informed,

March 19, 2026

Nuvotronics to Showcase High-Performance Radio Frequency (RF) and mmWave Solutions at Satellite 2026

Nuvotronics to Showcase High-Performance Radio Frequency (RF) and mmWave Solutions at Satellite 2026

DURHAM, NC / ACCESS Newswire / March 19, 2026 / Nuvotronics, a leader in high-performance RF and mmWave solutions for

March 19, 2026

Live Stem Cell and Exosome Therapy Now in Florida

Live Stem Cell and Exosome Therapy Now in Florida

Live Stem Cell Therapy in Miami: Florida's First Domestic Alternative to Overseas Treatment New York, United States –

March 19, 2026

Cornerstone BTI Delivers Enterprise-Grade IT Solutions to DFW SMBs

Cornerstone BTI Delivers Enterprise-Grade IT Solutions to DFW SMBs

Transforming IT Support for Small Businesses in Dallas-Fort Worth Richardson, United States – March 18, 2026 /

March 19, 2026

Discover Premium Canvas Hunting Tents for Your Next Adventure

Discover Premium Canvas Hunting Tents for Your Next Adventure

Explore the Best Wall Tents for Hunting This Season Moscow, United States – March 18, 2026 / Wall Tent Shop / As the

March 19, 2026

Affordable Implants Made Easy: Tips to Lower Your Dental Costs

Affordable Implants Made Easy: Tips to Lower Your Dental Costs

A Complete Guide to Getting Affordable Dental Implants in Denton,Texas denton, United States – March 18, 2026 /

March 19, 2026

First Class Trucking Enhances JFK Air Cargo Trucking Services

First Class Trucking Enhances JFK Air Cargo Trucking Services

Revolutionizing JFK Air Cargo Trucking Services with Precision and Speed Hallandale Beach, United States – March 18,

March 19, 2026

Brothers Motors LLC Offers Transparent Used Car Buying in Van Nuys

Brothers Motors LLC Offers Transparent Used Car Buying in Van Nuys

Discover Value-Driven Used Cars at Brothers Motors LLC in Van Nuys Canoga Park, United States – March 18, 2026 /

March 19, 2026

Prince Silver Delivers Further Strong Drill Results, Highlighted by 7.62 Metres of 230 G/T Silver, 10.78% Manganese, 1.87% Lead, 2.54% Zinc and 0.58 G/T Gold

Prince Silver Delivers Further Strong Drill Results, Highlighted by 7.62 Metres of 230 G/T Silver, 10.78% Manganese, 1.87% Lead, 2.54% Zinc and 0.58 G/T Gold

VANCOUVER, BC / ACCESS Newswire / March 19, 2026 / Prince Silver Corp. (CSE:PRNC)(OTCQB:PRNCF)(T130:Frankfurt) (“Prince Silver” or the “Company”), is pleased to announce a new…

March 19, 2026

Geistlich Awards Spartanburg, SC Periodontist with Trip to International Osteology Symposium Vienna 2026

Geistlich Awards Spartanburg, SC Periodontist with Trip to International Osteology Symposium Vienna 2026

Geistlich is thrilled to announce Dr. Chris Conzett, from Spartanburg, SC, as the grand prize winner of the “Talkin’

March 19, 2026

Homeowner Payments to Contractors Increased Almost 15% in 2025, iWallet Data Shows

Homeowner Payments to Contractors Increased Almost 15% in 2025, iWallet Data Shows

An analysis of payments processed through the iWallet platform shows total homeowner payments rose from $18.75 million

March 19, 2026

Nonprofit Leader Launches Two Apps to Assess Donor Emotional Alignment and Propensity

Nonprofit Leader Launches Two Apps to Assess Donor Emotional Alignment and Propensity

donorassess.org and transactandtransform.org deliver the relational intelligence the sector has never had — and now

March 19, 2026