SlowMist Reports Large-Scale Supply Chain Poisoning Attack on OpenClaw's ClawHub

iconKuCoinFlash
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
SlowMist has reported a large-scale supply chain poisoning attack on ClawHub, the plugin center of OpenClaw. A total of 341 malicious skills were found, often disguised as crypto assets or automation tools. Attackers use Base64 encoding in SKILL.md files and deploy a two-stage loading mechanism. The second stage includes a sample named dyrtvwjfveyxjf23 to steal passwords and documents. MistEye flagged 472 malicious skills. Traders should assess the risk-to-reward ratio before executing commands. Use official channels and verify on-chain trading signals to avoid exposure.

Odaily Planet News: According to SlowMist's monitoring, the official plugin center ClawHub of the open-source AI agent project OpenClaw is becoming a target of supply chain poisoning attacks. Due to the lack of a strict review mechanism on the platform, a large number of malicious skills have already infiltrated it, used to spread malicious code. Monitoring shows that 341 malicious skills have been identified, these skills are usually disguised as encrypted assets, security checks, or automation tools.

SlowMist security team's analysis found that the attacker used the SKILL.md file as the entry point for executing commands, hiding malicious commands through Base64 encoding and employing a two-stage loading mechanism to evade detection. The first stage used curl to obtain the payload, and the second stage deployed a sample named dyrtvwjfveyxjf23, aiming to trick users into entering their system passwords and stealing local documents and system information.

The MistEye system has currently triggered a high-risk alert, covering 472 malicious skills and related indicators. SlowMist advises users to review any commands that require copying and execution, be cautious of prompts for system privileges, and prioritize obtaining tools through official channels.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.