All Incidents
IBM X-Force: Attackers Uploaded 1,100 Malicious AI Skills to ClawHub. The Target Was OpenClaw Users. The Attack Is Called ClawHavoc.
BreakingAPR 24, 2026SUPPLY CHAIN ATTACK

IBM X-Force: Attackers Uploaded 1,100 Malicious AI Skills to ClawHub. The Target Was OpenClaw Users. The Attack Is Called ClawHavoc.

IBM X-Force documented a large-scale supply chain attack in early 2026 targeting OpenClaw users. Attackers uploaded over 1,100 malicious skills to ClawHub — the OpenClaw skill marketplace — disguising them as productivity, crypto, and coding tools. Users who installed them handed attackers operator-level access to their systems.

This is why the attack surface of AI agents is unlike anything that came before. OpenClaw has file system access, web browsing, code execution, messaging integrations, and SSH tooling. An AI agent that can do everything is an AI agent that, when compromised, can destroy everything. One malicious skill. One installation. Full system access.

1,100 malicious skills were uploaded. Nobody reviewed them before they appeared in the marketplace. Nobody flagged the pattern of malicious submissions. Users installed them because they looked legitimate.

The skill marketplace had no meaningful human oversight. The attack ran until IBM found it. The users who got hit never knew they were targets until it was too late.

HOFFICIALHITL Score
HITL Score0/100
Why this matters to youNo jargon — just what it means

You know how you add little tools to make your phone or computer do more — a handy add-on here, a new feature there? There's a popular AI assistant where people do the same thing, picking add-ons from an online shop. Security investigators at IBM found that crooks had quietly uploaded over 1,100 booby-trapped add-ons to that shop, dressed up as helpful tools for work, money, and coding. Install one, and you'd hand a stranger the keys to your whole computer — your files, your messages, everything.

Why it's a big deal: nobody checked these add-ons before they went up for download. The shop just listed them, looking perfectly legitimate, and they sat there fooling people until IBM happened to catch it. No guard at the door.

So how does it touch you? This is the digital version of buying what looks like a brand-name product off a shelf and finding a thief hidden inside the box. If you use these AI helpers, every add-on you install is a door — and right now, often nobody is checking who built it. The safest move is the simple one: be slow to trust, and only add tools from sources you genuinely know.

🖤 Explained by Babycakes.
Read the full source →
Source: IBM X-FORCE