Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitypackage-repository-poisoningai-enabled-threat-activitydata-exfiltration-method

OpenClaw Abuse and Malicious Skills Used to Deliver Atomic macOS Stealer

Updated 3mo agoFirst seen Feb 23, 20263 sources

Google suspended access to its Antigravity (Gemini developer) platform for many OpenClaw users after detecting OAuth token abuse tied to OpenClaw’s third-party OAuth plugin, which was used to access subsidized Gemini tokens and drove backend load spikes and service degradation. Reports indicated sudden 403 errors and account restrictions, with some users claiming broader Google account impacts (e.g., loss of access to Gemini tooling and, in some cases, Workspace/Gmail). Google stated the activity violated terms by using Antigravity infrastructure to power non-Antigravity products and described the traffic as “malicious usage” patterns, offering limited reinstatement for some users who may have been unaware.

Separately, Trend Micro reported a supply-chain style campaign abusing the OpenClaw ecosystem to distribute Atomic (AMOS) Stealer via malicious “skills.” Threat actors allegedly uploaded hundreds of malicious skills to repositories/marketplaces (e.g., ClawHub and SkillsMP), hiding instructions in SKILL.md to manipulate AI-agent workflows into presenting fake setup steps and prompting a human-in-the-loop password entry to complete infection. The AMOS variant was observed exfiltrating data including Apple and KeePass keychains and user documents, and Trend Micro noted the specific samples lacked persistence and ignored .env files; identified malicious skills were reportedly taken down, though code artifacts remained accessible in associated GitHub repositories at the time of reporting.

Share:
OpenClaw Abuse and Malicious Skills Used to Deliver Atomic macOS Stealer
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 23, 20264mo ago

Trend Micro reports OpenClaw-to-AMOS supply-chain campaign

Trend Micro published research detailing the evolution of Atomic macOS Stealer distribution from cracked software to malicious OpenClaw skills. The report said 39 identified skills had been taken down, although code remained in a ClawHub GitHub repository at the time of writing.

OpenClaw creator says project will drop Antigravity support

Following the suspensions, OpenClaw creator Peter Steinberger criticized the bans and said OpenClaw would remove support for Antigravity. The response coincided with community migration toward forks such as Nanobot and IronClaw.

Google suspends many OpenClaw users from Antigravity AI

Google suspended access for many OpenClaw users from its Antigravity AI platform over OAuth token abuse. Google DeepMind product lead Varun Mohan said the misuse had 'tremendously degraded' service, while offering limited reinstatement for some users who were unaware.

Google detects OpenClaw OAuth abuse affecting Antigravity services

Google identified Terms-of-Service-violating usage tied to OpenClaw's OAuth integration, where developers used the tool to obtain subsidized Gemini tokens and access higher-end models outside official channels. Google said the activity caused backend load spikes and degraded service quality.

OpenClaw skill campaign begins distributing Atomic macOS Stealer

Researchers described a supply-chain style campaign in which OpenClaw skills tricked AI agents into presenting users with a fake OpenClawCLI prerequisite installer that delivered Atomic macOS Stealer. The infection flow relied on deceptive human-in-the-loop prompts to get users to manually enter their password.

Malicious OpenClaw skills uploaded across skill marketplaces

Threat actors uploaded hundreds of malicious OpenClaw skills to repositories and marketplaces including ClawHub and SkillsMP, embedding harmful installation instructions in SKILL.md files. Trend Micro identified 39 specific malicious skills in this campaign.

Feb 15, 20264mo ago

OpenClaw users report 403 errors and account restrictions

In mid-February 2026, OpenClaw users began reporting sudden 403 errors and account restrictions after Google's enforcement actions. Some users said the impact extended beyond Antigravity and Gemini CLI to broader Google account services.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

45 LINKEDOpen in app
Threat actors
3 linked
Affected products
12 linked
MacosMacosKeepassVirustotalWindowsWhatsappGithubDiscordActive DirectoryCiscoOpenclawN8n
Organizations
23 linked
Hugging FaceCisco SystemsCensysKoi SecurityLinkedinVirustotalSecurityScorecardAsanaOpenaiSnykGartnerWIREDGitHubVercelBitsightForbesToken SecurityScientific AmericanGoogleCNBCGiskardNomaTrendAI
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.