Techub News reports that according to SlowMist monitoring, the open-source AI agent project OpenClaw's official plugin center ClawHub is becoming a target for supply chain poisoning attacks. Due to the platform's lack of strict review mechanisms, a large number of malicious Skills have infiltrated and are being used to spread malicious code. According to Koi Security, 341 malicious Skills have been identified so far, and these Skills are often disguised as crypto assets, security checks, or automation tools. SlowMist recommends users review any commands that need to be copied and executed, be cautious of prompts requesting system permissions, and prioritize obtaining tools through official channels.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Techub News reports that according to SlowMist monitoring, the open-source AI agent project OpenClaw's official plugin center ClawHub is becoming a target for supply chain poisoning attacks. Due to the platform's lack of strict review mechanisms, a large number of malicious Skills have infiltrated and are being used to spread malicious code. According to Koi Security, 341 malicious Skills have been identified so far, and these Skills are often disguised as crypto assets, security checks, or automation tools. SlowMist recommends users review any commands that need to be copied and executed, be cautious of prompts requesting system permissions, and prioritize obtaining tools through official channels.