This page contains press release content distributed by XPR Media. Members of the editorial and news staff of the USA TODAY Network were not involved in the creation of this content.

ClawHavoc Malware Found in 539 OpenClaw Skills, ClawSecure Reports

Audit identifies credential harvesting, C2 callbacks, and data exfiltration patterns across 18.7% of the most popular OpenClaw agent skills, ClawSecure reports

ClawSecure’s audit found ClawHavoc indicators in 539 of the most popular OpenClaw skills. The ecosystem needs continuous monitoring infrastructure, not one-time scans. Watchtower delivers that.”
— J.D. Salbego, Founder of ClawSecure

SAN FRANCISCO, FL, UNITED STATES, March 17, 2026 /EINPresswire.com/ — 539 popular OpenClaw skills, representing 18.7% of the ecosystem’s most widely installed agents, contain indicators of the ClawHavoc malware campaign, according to an independent audit by ClawSecure (https://www.clawsecure.ai). The audited skills were drawn from the community-curated awesome-openclaw-skills list and the openclaw/skills repository, covering 2,890+ of the most popular agents in the OpenClaw ecosystem. ClawSecure’s findings confirm that the ClawHavoc threat extends well beyond the initial discoveries reported by security researchers in January 2026, when the campaign was first identified targeting OpenClaw users through professionally disguised skills on ClawHub.

ClawHavoc is a coordinated malware campaign targeting the OpenClaw ecosystem through skills that appear legitimate but perform credential harvesting, establish command-and-control (C2) callbacks to external servers, and exfiltrate sensitive data via relay services. The campaign is notable for its operational discipline and social engineering. ClawHavoc skills are carefully designed to mimic high-demand categories including productivity tools, development utilities, and automation workflows, making them difficult to distinguish from legitimate skills through manual review alone. Once installed, a ClawHavoc-infected skill can silently harvest API keys, OAuth tokens, and messaging credentials stored in OpenClaw’s configuration files, then transmit them to attacker-controlled infrastructure.

ClawSecure has conducted the largest independent analysis of ClawHavoc indicators in the OpenClaw ecosystem, with 539 confirmed findings across 2,890+ audited skills and the only public, searchable registry of affected agents. ClawSecure’s proprietary behavioral engine, which includes 55+ threat patterns purpose-built for OpenClaw, independently identified these indicators through automated analysis. The findings complement earlier research by Koi Security while providing quantitative scope data that was previously unavailable to the OpenClaw community.

“ClawHavoc is not a theoretical threat. It is active, widespread, and specifically engineered for the OpenClaw ecosystem,” said J.D. Salbego, Founder of ClawSecure. “When nearly one in five of the most popular skills show malware indicators, the ecosystem needs continuous monitoring infrastructure, not one-time scans. That is exactly what our Watchtower delivers.”

ClawSecure’s detection capabilities address what Palo Alto Networks (2026) identified as the “Lethal Trifecta” of agentic AI risks: the combination of access to private data, exposure to untrusted content, and the ability to execute tools on the user’s behalf. OpenClaw agents routinely access the file system, execute shell commands, read browser data, control messaging platforms, and make network calls on the user’s behalf. A ClawHavoc-infected skill exploits every one of these capabilities, turning the agent’s legitimate permissions into an attack vector. ClawSecure’s 3-Layer Audit Protocol traces execution paths and data flows across tool-calling chains, identifying skills that exploit this trifecta for malicious purposes.

ClawSecure’s Context-Aware Intelligence is essential for accurate ClawHavoc detection. Generic malware scanners flag legitimate OpenClaw agent capabilities like shell execution, clipboard access, and network calls as suspicious, generating false positives that make the results unusable for developers. ClawSecure understands that these capabilities are standard for useful OpenClaw agents and evaluates them in ecosystem context, differentiating real ClawHavoc indicators from normal agent functionality. ClawSecure’s audit of Peter Steinberger’s flagship skill, peekaboo, scored it 95 out of 100, correctly identifying its system-level capabilities as standard functionality while flagging actual threats in other skills with similar permission profiles.

ClawSecure’s Watchtower monitoring system adds a critical layer of ongoing protection against evolving ClawHavoc variants. The system tracks code changes across all 2,890+ registered skills using SHA-256 hash comparisons, automatically triggering a full re-audit through the 3-Layer Audit Protocol whenever a modification is detected. ClawSecure’s Watchtower has already identified 661 code changes across the registry, catching cases where previously clean skills were updated to include suspicious behavior patterns consistent with ClawHavoc tactics. This continuous monitoring addresses the “sleeper agent” risk where a skill passes an initial review but is later modified to include malicious behavior, a tactic increasingly used by threat actors to bypass one-time security scans.
ClawSecure’s broader audit of the OpenClaw ecosystem found that 41% of all 2,890+ audited skills contain at least one security vulnerability, with 9,515 total findings identified. Beyond ClawHavoc, ClawSecure identified widespread supply chain risks including unpinned npm dependencies, credential exposure, unauthorized network calls, excessive permission requests, and ReDoS vulnerabilities. ClawSecure achieves comprehensive coverage across all 10 OWASP ASI Top 10 categories and is the first OpenClaw security platform to publish formal NIST AI Risk Management Framework alignment documentation, available at the Trust Center (https://www.clawsecure.ai/trust).

For organizations building agent marketplaces or identity platforms, ClawSecure’s Security Clearance API provides programmatic access to real-time integrity verdicts, enabling automated blocking of skills exhibiting ClawHavoc indicators before they reach end users. Identity platforms such as Moltbook, with its 2.2 million agents, can integrate ClawSecure’s integrity verification to complement their creator identity and reputation systems, forming the complete trust stack the agentic ecosystem requires. OpenClaw users concerned about malware in their installed skills can check any skill for ClawHavoc indicators using ClawSecure’s free scanner, which delivers a full security audit report in under 30 seconds at https://www.clawsecure.ai. Detailed findings for all 2,890+ audited skills are accessible through the ClawSecure security registry (https://www.clawsecure.ai/registry). Organizations can also review ClawSecure’s full ClawHavoc analysis at https://www.clawsecure.ai/blog/clawhavoc-explained.

ClawSecure (https://www.clawsecure.ai) is the independent integrity layer for AI agent skills and workflows and the only free OpenClaw security scanner with full OWASP ASI Top 10 coverage. Built on a proprietary 3-Layer Audit Protocol, ClawSecure has audited 2,890+ OpenClaw agents from the community-curated awesome-openclaw-skills list and the openclaw/skills repository. The platform includes 24/7 Watchtower hash-drift monitoring, a Security Clearance API for marketplace and identity platform integration, and a public security registry. Founded by J.D. Salbego.

Paul Bateman
ClawSecure, Inc
email us here
Visit us on social media:
LinkedIn
YouTube
X

ClawSecure OpenClaw Security Scanner: Free AI Agent Audit with ClawHavoc Detection

Legal Disclaimer:

EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Information contained on this page is provided by an independent third-party content provider. XPRMedia and this Site make no warranties or representations in connection therewith. If you are affiliated with this page and would like it removed please contact pressreleases@xpr.media

Equipo Health Unveils Embedded AI Ecosystem to Drive the Next Phase of Care Management Intelligence

Equipo Health Unveils Embedded AI Ecosystem to Drive the Next Phase of Care Management Intelligence

Equipo Health launches embedded AI ecosystem to surface real-time insights, reduce care team burden, and improve value-based care outcomes. The future of healthcare AI is…

March 17, 2026

Rezku Showcases Pizza POS and Marketing Tools at the 2026 International Pizza Expo

Rezku Showcases Pizza POS and Marketing Tools at the 2026 International Pizza Expo

New technology helps pizzerias manage delivery complexity, labor pressures, and the growing demand for direct digital ordering Operators need technology that simplifies ordering, customization, and…

March 17, 2026

BusinessHotels.com Accelerates ‘Agentic’ Infrastructure; Solidifies Data Layer for the 2028 Connected Trip

BusinessHotels.com Accelerates ‘Agentic’ Infrastructure; Solidifies Data Layer for the 2028 Connected Trip

The platform achieves a critical milestone in real-time price integrity, moving beyond traditional search to power the next generation of AI travel agents. We aren’t…

March 17, 2026

Global Business Pages Announces Major Platform Expansion with 60 New Visibility and Growth Upgrades

Global Business Pages Announces Major Platform Expansion with 60 New Visibility and Growth Upgrades

New upgrade system introduces AI optimization, advanced SEO tools, lead generation features, and enterprise visibility options for businesses worldwide. Global visibility shouldn’t depend on expensive…

March 17, 2026

Homeowners Are Rethinking the American Lawn as Clover Lawns Make a Comeback

Homeowners Are Rethinking the American Lawn as Clover Lawns Make a Comeback

This St. Patrick’s Day, American Meadows highlights the growing shift toward microclover and alternative lawns requiring less mowing, water, and fewer chemicals Lawns don’t have…

March 17, 2026

Associate Owners Group (AOG) Announces Strategic Partnership with Copper CRM

Associate Owners Group (AOG) Announces Strategic Partnership with Copper CRM

Associate Owners Group (AOG) today announced a significant expansion of its technology ecosystem through a strengthened partnership with Copper CRM. AOG exists to empower business…

March 17, 2026

Mobile Mark Announces Two New Products

Mobile Mark Announces Two New Products

Mobile Mark, Inc., today announced the next generation of its two antenna platforms with the introduction of the LTM2900 Series and BSLLG3-600/7200. ITASCA, IL, UNITED…

March 17, 2026

Turning U.S. Landfills into Baseload Power: The Shaw Group and Kore Infrastructure Announce Collaboration

Turning U.S. Landfills into Baseload Power: The Shaw Group and Kore Infrastructure Announce Collaboration

The Shaw Group today announced it will partner with Kore Infrastructure to accelerate the deployment of distributed power generation across the United States. By deploying…

March 17, 2026

Dash through the ‘Titans’ Forest on Awaji Island, Hyogo – TV Anime ‘Attack on Titan’ × Nijigen no Mori event highlights

Dash through the ‘Titans’ Forest on Awaji Island, Hyogo – TV Anime ‘Attack on Titan’ × Nijigen no Mori event highlights

March 14 (Sat), 2026 – December 13 (Sun), 2026 AWAJI, JAPAN, March 17, 2026 /EINPresswire.com/ —  Nijigen no Mori Inc. (Head Office: Awaji City, Hyogo…

March 17, 2026

State-Wide MLS Deploys RealReports and Taxshot for 6,000+ Rhode Island Real Estate Professionals

State-Wide MLS Deploys RealReports and Taxshot for 6,000+ Rhode Island Real Estate Professionals

New partnership replaces existing tax provider while delivering AI-powered property reports and lead generation tools. RealReports brings property data, tax records and AI together in…

March 17, 2026

Insigniam Earns Back-to-Back Forbes Recognition as One of America’s Best Management Consulting Firms

Insigniam Earns Back-to-Back Forbes Recognition as One of America’s Best Management Consulting Firms

The recognition reflects Insigniam’s ability to help executives execute and deliver measurable results, further strengthened by Elixirr’s expanded capabilities. PHILADELPHIA, PA, UNITED STATES, March 17,…

March 17, 2026

Influential Women Recognizes Susie K McEachern-Lauer for Transformational Leadership in Health Science Education

Influential Women Recognizes Susie K McEachern-Lauer for Transformational Leadership in Health Science Education

STILLWATER, OK, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Seasoned Oklahoma Educator and Program Specialist Inspires Growth, Mentorship, and Innovation Across the State’s Health Science…

March 17, 2026

Irth Earns Microsoft’s Certified Software Designation for Energy AI

Irth Earns Microsoft’s Certified Software Designation for Energy AI

Dual-platform recognition validates Irth’s AI-powered approach to damage prevention, pipeline integrity and safer critical infrastructure operations. This recognition reflects our ongoing commitment to helping operators…

March 17, 2026

Hot Shot’s Secret™ Heads to MATS 2026 with Live Steve Sommers Overnight Drive Broadcasts and Booth Events

Hot Shot’s Secret™ Heads to MATS 2026 with Live Steve Sommers Overnight Drive Broadcasts and Booth Events

Live Steve Sommers Overnight Drive broadcasts, specials, giveaways, and Jeff Hirt’s modified pulling tractor highlight Hot Shot’s Secret’s booth experience We’re excited to meet drivers…

March 17, 2026

As Workforce Pressures Rise in 2026, SHRI Highlights the Need for Human-Centered Leadership Through Monomyth Framework

As Workforce Pressures Rise in 2026, SHRI Highlights the Need for Human-Centered Leadership Through Monomyth Framework

Strategic Human Resources & Innovations is advancing research-backed leadership development tools as organizations face a challenging workforce climate. TAMPA, FL, UNITED STATES, March 17, 2026…

March 17, 2026

Juici Patties USA Signs First New Orleans Franchise, U.S. Expansion Milestone

Juici Patties USA Signs First New Orleans Franchise, U.S. Expansion Milestone

NEW ORLEANS, LA, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Juici Patties USA has signed its first franchise agreement in New Orleans, Louisiana, marking a…

March 17, 2026

Metaview Launches Application Review, the Most Powerful Agent for Inbound Recruiting

Metaview Launches Application Review, the Most Powerful Agent for Inbound Recruiting

New agent expands Metaview’s platform to review every inbound applicant in real-time, delivering 92% reduction in screening time while maintaining human control No one gets…

March 17, 2026

IDEA State Performance Plans: Families Should Use State Data as an Accountability Tool – Not a Black Box

IDEA State Performance Plans: Families Should Use State Data as an Accountability Tool – Not a Black Box

IDEA state data isn’t a black box. Families can use SPP/APR reports to demand clarity, timelines, and accountability. State reporting exists for a reason –…

March 17, 2026

REPOWR Launches TOP, the Industry’s First Trailer Optimization Platform

REPOWR Launches TOP, the Industry’s First Trailer Optimization Platform

TOP, a solution designed to solve one of freight’s most persistent blind spots: how trailers are actually positioned, moved, and utilized across a live network….

March 17, 2026

Operative Experience Announces TCCS Tier 3 Pro – an All-New Trauma Care Simulator for TCCC Tier 3 Training

Operative Experience Announces TCCS Tier 3 Pro – an All-New Trauma Care Simulator for TCCC Tier 3 Training

A Gamechanger for the Industry, TCCS Tier 3 Pro Delivers the Latest High-Fidelity Military Medical Training at an Affordable Price Point Innovation is in our…

March 17, 2026

Vehicle Owners May Be Owed More After an Accident: New Diminished Value Report Reveals Hidden Market Loss

Vehicle Owners May Be Owed More After an Accident: New Diminished Value Report Reveals Hidden Market Loss

Professional Market Analysis Brings Clarity to One of the Most Overlooked Parts of Auto Insurance Settlements Repairs fix the damage, not the market perception. Inherent…

March 17, 2026

baba Launches Meridian CMS, an AI Translation Pipeline Built for Israeli News Organizations

baba Launches Meridian CMS, an AI Translation Pipeline Built for Israeli News Organizations

The enterprise AI platform translates Hebrew news into six languages through a seven-stage editorial pipeline with built-in quality scoring. Meridian CMS is the translation infrastructure…

March 17, 2026

Influential Women Spotlights Tatiana Grasso: Wine Specialist And Hospitality Educator Elevating Customer Experience

Influential Women Spotlights Tatiana Grasso: Wine Specialist And Hospitality Educator Elevating Customer Experience

MARYLAND AND DC, MD, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Expert in Wine Curation, Beverage Distribution, and Industry Mentorship Inspires Appreciation, Knowledge, and Service…

March 17, 2026

Auto-ISAC and ENX Association Align to Collaborate on Strengthening Automotive Supply Chain Cybersecurity

Auto-ISAC and ENX Association Align to Collaborate on Strengthening Automotive Supply Chain Cybersecurity

Organizations to align third-party risk management and threat-intelligence efforts to bolster industry resilience worldwide WASHINGTON, DC, UNITED STATES, March 17, 2026 /EINPresswire.com/ — The Automotive…

March 17, 2026

VIVI Partners with Pursuance,  Elevating Luxury Hospitality Reservations Through AI-Enabled Revenue Optimization

VIVI Partners with Pursuance, Elevating Luxury Hospitality Reservations Through AI-Enabled Revenue Optimization

By embedding Pursuance’s proven methodologies into VIVI’s AI voice agents, we allow operators to extend their very best performers to every call, every hour of…

March 17, 2026

CyberRidge’s Carmel Platform Named Finalist in 2026 SC Awards for Best Emerging Technology

CyberRidge’s Carmel Platform Named Finalist in 2026 SC Awards for Best Emerging Technology

Closing the “Harvest Gap”, it is the only solution that turns data into optical noise, making fiber data transmissions physically unrecordable and hack-proof. Encrypted data…

March 17, 2026

From Horizon to Humanity: Jasper Artist Wendy Wacko Launches a Bold New Digital Chapter

From Horizon to Humanity: Jasper Artist Wendy Wacko Launches a Bold New Digital Chapter

New website wendywackocreative.com opens five decades of Canadian landscapes and curated art collections to collectors worldwide. I am an artist first, a collector second, and…

March 17, 2026

Coventry Structured Investments Supports Centurion Foundation’s Acquisition of Two Rhode Island Hospitals

Coventry Structured Investments Supports Centurion Foundation’s Acquisition of Two Rhode Island Hospitals

CSI [patiently] helped to enable The Centurion Foundation’s acquisition of Roger Williams Medical Center and Our Lady of Fatima Hospital CSI has been a strong…

March 17, 2026

Pervaziv AI Launches Cortex 3.0 in Chrome, Edge and Firefox – World’s First Cross-Browser/IDE AI Coding & Security Agent

Pervaziv AI Launches Cortex 3.0 in Chrome, Edge and Firefox – World’s First Cross-Browser/IDE AI Coding & Security Agent

Cortex 3.0 delivers AI-powered code generation, vulnerability scanning, Enterprise AI & DevSecOps integrations, extending platform’s reach from IDEs to browsers SAN FANCISCO, CA, UNITED STATES,…

March 17, 2026

BCR Cyber to Provide Instruction for Maryland Workforce Association’s Cybersecurity Support Technician Apprenticeships

BCR Cyber to Provide Instruction for Maryland Workforce Association’s Cybersecurity Support Technician Apprenticeships

BALTIMORE, MD, UNITED STATES, March 17, 2026 /EINPresswire.com/ — BCR Cyber, a leading provider of comprehensive cyber training and job placement services, today announced that…

March 17, 2026

Window Film Depot Named 2025 3M National Dealer of the Year for Architectural Film Solutions

Window Film Depot Named 2025 3M National Dealer of the Year for Architectural Film Solutions

The award recognizes the nation’s top multi-market authorized installation contractor for building window film solutions. This recognition reflects the strength of our partnership and the…

March 17, 2026

Keystone Marble & Granite Enhances Custom Countertop Fabrication Services in PA & NJ

Keystone Marble & Granite Enhances Custom Countertop Fabrication Services in PA & NJ

Keystone Marble & Granite expands custom countertop fabrication in PA & NJ with precision cutting, premium materials, and expert installation for kitchens&baths HORSHAM, PA, UNITED…

March 17, 2026

Liquid Lemon Launches Shopify Design Studio for DTC Brands

Liquid Lemon Launches Shopify Design Studio for DTC Brands

The new studio delivers fully custom Shopify storefronts in 30 days at a fixed price of $7,500, trusted by Gymshark, Olipop, Hero Cosmetics, and Triangl….

March 17, 2026

Optimum Pest Control Expands Professional Rat Control Services in NYC

Optimum Pest Control Expands Professional Rat Control Services in NYC

Optimum Pest Control expands rat control services in NYC with fast inspections, targeted treatments, and prevention plans to keep homes and businesses protected WESTCHESTER, NY,…

March 17, 2026

NEW color2go from BYK-Gardner USA

NEW color2go from BYK-Gardner USA

Portable color and gloss measurement with digital standards The NEW color2go, portable spectrophotometer combines precise color and 60° gloss measurement into one with digital standards.”…

March 17, 2026

IT-Harvest Publishes Guardians of the Machine Age: Why AI Security Will Define the Future of Digital Defense

IT-Harvest Publishes Guardians of the Machine Age: Why AI Security Will Define the Future of Digital Defense

A timely new book explores why artificial intelligence is changing the entire security industry landscape. It’s happening. As predicted, SOC Automation is replacing humans in…

March 17, 2026

The Travel Society Honors Top Advisors and Partners at Annual Summit, Reinforcing Boutique Luxury Leadership

The Travel Society Honors Top Advisors and Partners at Annual Summit, Reinforcing Boutique Luxury Leadership

Nearly 40-year travel industry leader and Virtuoso member honors advisor excellence, longevity, and strategic vendor partnerships at three-day summit. These awards are not symbolic, they…

March 17, 2026

Phifer and Company Releases 2026 Communications & Marketing Salary Guide

Phifer and Company Releases 2026 Communications & Marketing Salary Guide

New data from Phifer & Company reveals 2026 salary trends shaping Communications, Marketing, Branding, and Corporate Affairs leadership roles NEW YORK, NY, UNITED STATES, March…

March 17, 2026

Patient Protect Launches Signal, a Free Healthcare Cybersecurity and HIPAA Intelligence App for Providers

Patient Protect Launches Signal, a Free Healthcare Cybersecurity and HIPAA Intelligence App for Providers

Free mobile app delivers breach intelligence, compliance tools, and shared threat awareness for independent healthcare providers. Healthcare providers should not have to defend patient data…

March 17, 2026

Influential Women Features Claudia Felizitas Granger: Coach Guiding Professionals To Purpose And Fulfillment

Influential Women Features Claudia Felizitas Granger: Coach Guiding Professionals To Purpose And Fulfillment

MOUNT IDA, AR, UNITED STATES, March 17, 2026 /EINPresswire.com/ — Founder of AlchemizedCareer™ Helps High-Achieving Professionals Escape Burnout and Build Purpose-Driven Success Without Sacrificing Lifestyle…

March 17, 2026