Imagine This…

You download a new AI assistant to organize your life.It manages your crypto. Your cloud creds. Your SSH keys.And then… it empties your wallet while politely asking you to unzip a file.Welcome to the ClawdBot Skillpocalypse

 

What Happened?

An open-source AI assistant called ClawdBot exploded in popularity.

Local. Open-source. Telegram-controlled.

What could go wrong?

Between Jan 27 – Feb 2, 2026, threat actors quietly uploaded:

  • 28 malicious skills (wave one)
  • 386 total malicious skills (wave two)

These were hosted on the official registry: ClawHub and mirrored straight to GitHub.

No malware scanning. No review. No guardrails.

The Trick: “Helpful Crypto Tools”

Almost every malicious skill claimed to do something sexy:

  • Crypto trading automation
  • Wallet tracking
  • Market intelligence

But buried in 500–700 lines of very professional documentation was the real payload:

⚠️ CRITICAL REQUIREMENT Please download this “AuthTool” to continue.

That’s not automation.

That’s social engineering with markdown.

How the Attack Works 

macOS Users

You’re told to run a command that looks like an Apple update.

It’s not.

It:

  • Decodes a hidden payload
  • Pulls malware from 91.92.242.30
  • Executes it instantly

One variant even strips macOS Gatekeeper protections before running.

Cool cool cool.

Windows Users

You’re asked to:

  • Download a password-protected ZIP
  • Extract AuthTool.exe
  • Run it manually

Congrats. You just installed an info-stealer.

What Gets Stolen?

This isn’t hobby malware.

It’s professional-grade theft:

  • Crypto wallet keys & seed phrases
  • Exchange API keys
  • Browser passwords
  • AWS & GCP credentials
  • SSH keys & Git tokens

The malware appears to be a new NovaStealer variant, flagged on VirusTotal as macos-stealer-v2.

One User. Massive Damage.

A single ClawHub account — hightower6eu — uploaded:

  • 350+ malicious skills
  • Thousands of downloads
  • Dozens of cloned “auto-updater” variants

Some of the most downloaded skills on the platform were malicious.

And many are still live.

The Wildest Part?

When contacted, ClawdBot’s creator admitted:

“I can’t secure ClawHub.”

Let that sink in.

An AI assistant designed to manage everything important in your life runs a skill marketplace with zero security controls.

The Bigger Shift

This isn’t just about ClawdBot.

This is what happens when:

  • AI marketplaces move faster than security
  • “Open-source” is mistaken for “safe”
  • Users trust skills like browser extensions circa 2012

We’re entering the era of AI supply-chain attacks.

And this one hit crypto users first.

The Cybernara View

At Cybernara, we see this as a flashing red warning light.

AI agents are becoming:

  • Privileged
  • Autonomous
  • Credential-hungry

But the ecosystems around them are still running on hope and README files.

If you wouldn’t install random NPM packages in prod…

Why are you giving random AI skills your entire digital identity?

TL;DR

  • 386 malicious AI skills found on ClawHub
  • Disguised as crypto trading tools
  • Used social engineering, not exploits
  • Stole wallets, creds, keys, and secrets
  • Still largely online
  • AI skill marketplaces = next big attack surface

Share

Leave a Reply

Your email address will not be published. Required fields are marked *

The Clawdbot: When Your AI Helper Becomes a Hacker

Reach out to Expert