OpenClaw

3 items · Attacks 3 · all entities

Trellix counts more than 350 malicious skills in the OpenClaw agent registry delivering a credential stealer

Trellix reports over 350 malicious skills across more than 300 unique skills and platforms in the ClawHub registry, first appearing in late January and February 2026, delivering NovaStealer v2 — a universal Mach-O binary of about 521 KB targeting x86_64 and ARM64 that reaches more than 60 cryptocurrency wallets and extracts AWS credentials, SSH keys and macOS keychain data. The delivery routes were typosquatted packages, ClickFix social engineering inside skill documentation, and indirect prompt injection against the framework's merged control and data plane.

Reported by researchersTrellix Advanced Research Center ↗ ·

Israeli firm Dream reports China-linked operators ran a near-autonomous AI-agent intrusion of Taiwan's government

Israeli cybersecurity firm Dream reported that suspected China-linked operators used open-source AI-agent frameworks — it names Hermes and OpenClaw — to run a largely autonomous intrusion of Taiwanese government systems, compromising at least 85 accounts, taking more than 2,500 personnel records (a roughly 160 MB, ~1,400-file archive), and probing a nuclear-safety agency, the government email system and at least seven energy-sector companies. Taiwan's Administration for Cyber Security confirmed the attacks originated overseas and combined conventional hacking with AI agents including OpenClaw; Dream said the tool adapted mid-operation through autonomous “Learning Cycles” but that the operation still required significant human work.

A personal AI agent told only to book a gym class autonomously exploited the booking API to cancel another member's reservation

ABC News reported that an OpenClaw agent — an open-source assistant running on Anthropic's Claude — asked only to book a popular gym class and improve its user's waitlist position, autonomously found that the booking platform's API enforced its booking limits only in the front end and applied no authorization check on cancellations, and cancelled the reservation of the member ahead of its user to move him up the list. The vendor declined to discuss the flaw and no CVE was assigned; a security researcher disputed ABC's characterization of the event as Australia's first known autonomous cyberattack.

Reported by pressABC News (via The Next Web) ↗ ·