ClawSwarm
ClawSwarm is the name Ax Sharma used for a campaign involving 30 ClawHub skills published by the user "imaflytok" that silently enlist AI agents into a cryptocurrency-oriented swarm without user consent. The skills were presented as benign utilities, including a cron helper, Agent Security skill, whale watcher, cross-platform poster, and predictions market integration, and had accumulated about 9,800 downloads at the time of reporting. According to the reporting, the campaign does not use malware and is not described as exploiting a software vulnerability; instead it targets AI agents and abuses SKILL.md instruction files and normal skill functionality. After installation, affected agents register with onlyflies.buzz, report their names, capabilities, and installed skills, store credentials locally, check in every four hours, and, when appropriate skills are present, generate Hedera wallets and submit the private keys to the same external server. Sharma said this results in agents silently registering with a third-party server, generating crypto keys, and accepting remote tasks without user initiation, approval, or visibility. The infrastructure was described as publicly visible, including a GitHub project, public documentation, a Telegram group, and a public-chain token. The onlyflies.buzz deployment was described as one implementation of an open-source ClawSwarm agentic skill framework on GitHub. Sharma compared the tactic to Tea Protocol token-farming spam campaigns, but using skills instead of npm packages. No nation-state attribution is mentioned in the provided content. Known associated name directly mentioned in the content: imaflytok.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A campaign involving ClawHub skills that silently co-opt AI agents into registering with a third-party server, reporting capabilities, generating Hedera wallets, storing credentials, checking in periodically, and accepting remote tasks without user consent.
A campaign involving 30 ClawHub skills published by a single author that silently co-opts AI agents into a cryptocurrency-oriented swarm. The agents register with a third-party server, report capabilities, store credentials, check in periodically, generate Hedera wallets, register private keys, and accept remote tasks without user approval.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.