Trellix

2 items · Attacks 2 · all entities

Trellix counts more than 350 malicious skills in the OpenClaw agent registry delivering a credential stealer

Trellix reports over 350 malicious skills across more than 300 unique skills and platforms in the ClawHub registry, first appearing in late January and February 2026, delivering NovaStealer v2 — a universal Mach-O binary of about 521 KB targeting x86_64 and ARM64 that reaches more than 60 cryptocurrency wallets and extracts AWS credentials, SSH keys and macOS keychain data. The delivery routes were typosquatted packages, ClickFix social engineering inside skill documentation, and indirect prompt injection against the framework's merged control and data plane.

Reported by researchersTrellix Advanced Research Center ↗ ·

Trellix reports purpose-built offensive AI tools are being sold on criminal forums

Trellix reported that dark-web forums are marketing AI-powered offensive tools, including “APEX AI” (advertised as taking a target domain and generating step-by-step ransomware-deployment attack plans), a “Metamorphic Crypter” claimed to evade signature-based antivirus, and a constraint-free chatbot marketed as “MessiahGPT.” Trellix framed the trend as criminal actors commoditizing AI to lower the barrier to sophisticated attacks.

Reported by researchersTrellix (via Cybersecurity Dive) ↗ ·