BTCC / BTCC Square / Global Cryptocurrency /
ClawHub Marketplace Hosts Malicious AI Skills Targeting Crypto Wallets

ClawHub Marketplace Hosts Malicious AI Skills Targeting Crypto Wallets

Published:
2026-02-09 10:16:02
BTCCSquare news:

ClawHub, a marketplace for OpenClaw AI agent skills, is under scrutiny for hosting hundreds of malicious skills capable of supply chain attacks. Researchers identified credentials-stealing malware embedded in seemingly legitimate tools, including crypto wallet trackers and productivity apps.

SlowMist's analysis of 400+ compromised skills reveals organized attacks targeting specific domains. One skill, 'X Trends,' hides a backdoor downloader that exfiltrates credentials—potentially compromising linked crypto wallets. Earlier findings by KOI Security flagged 341 malicious skills among 2,857 listings; SlowMist later expanded this to 472.

Attack vectors include fake prerequisites. "The skill's documentation looks professional," notes KOI researcher Oren Yomtov, "but there’s a ‘Prerequisites’ section demanding suspicious downloads." A Windows exploit is actively circulating, amplifying risks for users who install these trojanized tools.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users