Imagine This…
You download a new AI assistant to organize your life.It manages your crypto. Your cloud creds. Your SSH keys.And then… it empties your wallet while politely asking you to unzip a file.Welcome to the ClawdBot Skillpocalypse
What Happened?
An open-source AI assistant called ClawdBot exploded in popularity.
Local. Open-source. Telegram-controlled.
What could go wrong?
Between Jan 27 – Feb 2, 2026, threat actors quietly uploaded:
- 28 malicious skills (wave one)
- 386 total malicious skills (wave two)
These were hosted on the official registry: ClawHub and mirrored straight to GitHub.
No malware scanning. No review. No guardrails.
The Trick: “Helpful Crypto Tools”
Almost every malicious skill claimed to do something sexy:
- Crypto trading automation
- Wallet tracking
- Market intelligence
But buried in 500–700 lines of very professional documentation was the real payload:
⚠️ CRITICAL REQUIREMENT Please download this “AuthTool” to continue.
That’s not automation.
That’s social engineering with markdown.
How the Attack Works
macOS Users
You’re told to run a command that looks like an Apple update.
It’s not.
It:
- Decodes a hidden payload
- Pulls malware from 91.92.242.30
- Executes it instantly
One variant even strips macOS Gatekeeper protections before running.
Cool cool cool.
Windows Users
You’re asked to:
- Download a password-protected ZIP
- Extract AuthTool.exe
- Run it manually
Congrats. You just installed an info-stealer.
What Gets Stolen?
This isn’t hobby malware.
It’s professional-grade theft:
- Crypto wallet keys & seed phrases
- Exchange API keys
- Browser passwords
- AWS & GCP credentials
- SSH keys & Git tokens
The malware appears to be a new NovaStealer variant, flagged on VirusTotal as macos-stealer-v2.
One User. Massive Damage.
A single ClawHub account — hightower6eu — uploaded:
- 350+ malicious skills
- Thousands of downloads
- Dozens of cloned “auto-updater” variants
Some of the most downloaded skills on the platform were malicious.
And many are still live.
The Wildest Part?
When contacted, ClawdBot’s creator admitted:
“I can’t secure ClawHub.”
Let that sink in.
An AI assistant designed to manage everything important in your life runs a skill marketplace with zero security controls.
The Bigger Shift
This isn’t just about ClawdBot.
This is what happens when:
- AI marketplaces move faster than security
- “Open-source” is mistaken for “safe”
- Users trust skills like browser extensions circa 2012
We’re entering the era of AI supply-chain attacks.
And this one hit crypto users first.
The Cybernara View
At Cybernara, we see this as a flashing red warning light.
AI agents are becoming:
- Privileged
- Autonomous
- Credential-hungry
But the ecosystems around them are still running on hope and README files.
If you wouldn’t install random NPM packages in prod…
Why are you giving random AI skills your entire digital identity?
TL;DR
- 386 malicious AI skills found on ClawHub
- Disguised as crypto trading tools
- Used social engineering, not exploits
- Stole wallets, creds, keys, and secrets
- Still largely online
- AI skill marketplaces = next big attack surface








