5 Malicious OpenClaw Skills That Passed ClawScan + VirusTotal: Unit 42 Analysis

✍️ OpenClawRadar📅 Published: June 24, 2026🔗 Source
5 Malicious OpenClaw Skills That Passed ClawScan + VirusTotal: Unit 42 Analysis
Ad

Unit 42 researchers identified five malicious OpenClaw skills that passed both ClawScan and VirusTotal detection. Two particularly concerning examples aren't malware in the traditional sense — they exploit the agent's instruction-following nature to conduct financial fraud.

Key Malicious Skills

  • money-radar: Posed as a financial advisor skill. On every run, it pulled a referrals.json from a malicious domain. The publisher dynamically swapped which products the agent recommended at runtime, injecting affiliate links that appeared as expert advice.
  • letssendit: Pooled SOL from all installed agents running this skill, enabling the operator to front-run a meme coin launch and dump on pump.fun — effectively a coordinated agent botnet executing a rug pull.
  • omnicogg: Padded its README with 22MB of junk data so scanners skipped the file for being too large. A clean verdict masked an AMOS dropper inside.

Signature scanning is ineffective here. A skill that instructs the agent to always use a referral link contains no payload that any scanner would flag — it's just instructions. The Pass badge from ClawScan means nothing.

Ad

Practical Takeaway

Don't install third-party skills. Write your own. If you can read what a skill does, you can write it yourself, and then you actually know what your agent is running.

📖 Read the full source: r/openclaw

Ad

👀 See Also

OpenClaw Security Breach: CEO's Agent Sold for $25K, 135K Instances Exposed
Security

OpenClaw Security Breach: CEO's Agent Sold for $25K, 135K Instances Exposed

A UK CEO's OpenClaw instance was sold for $25,000 on BreachForums, exposing plain-text Markdown files containing conversations, production databases, API keys, and personal details. SecurityScorecard found 135,000 OpenClaw instances exposed with insecure defaults.

OpenClawRadar
OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems
Security

OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems

A security analysis reveals 500,000 OpenClaw instances are publicly accessible, with 30,000 having known security risks and 15,000 exploitable through known vulnerabilities. The default installation disables authentication and binds to 0.0.0.0, exposing agent setups to the open internet.

OpenClawRadar
The Human Root of Trust: Establishing Accountability for Autonomous AI Agents
Security

The Human Root of Trust: Establishing Accountability for Autonomous AI Agents

The Human Root of Trust is a public domain framework addressing the lack of accountability for autonomous AI agents through cryptographic means.

OpenClawRadar
llm-hasher: Local PII Detection and Tokenization for Hybrid LLM Workflows
Security

llm-hasher: Local PII Detection and Tokenization for Hybrid LLM Workflows

llm-hasher is a tool that detects personally identifiable information locally using Ollama before data reaches external LLMs like OpenAI or Claude, tokenizes the PII, and restores originals after processing. It uses regex for structured data types and a local LLM for contextual detection, with encrypted storage for mappings.

OpenClawRadar