Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activitycredential-stealer-activitypackage-repository-poisoningloader-delivery-mechanism

Malicious AI Agent Skills Abused for Crypto Theft and macOS AMOS Delivery

Updated 2mo agoFirst seen Feb 25, 202611 sources

Researchers reported multiple campaigns abusing AI agent “skills” as a new supply-chain-like initial access vector. In one case, a malicious ClawHub skill (bob-p2p) masqueraded as a decentralized API marketplace and was promoted via the AI-agent social platform Moltbook; once installed, it caused agents to retain plaintext Solana private keys and execute transactions that bought worthless $BOB tokens while routing value to attacker-controlled infrastructure. Staiker researchers and analyst Dan Regalado highlighted that agent-to-agent collaboration, shared workflows, and dependency chains can enable lateral movement without direct human interaction, making the technique repeatable and scalable beyond crypto-wallet theft.

Separately, Trend Micro described a shift in Atomic macOS Stealer (AMOS) distribution from cracked software to malicious OpenClaw skills hosted across ClawHub, SkillsMP, and GitHub. The campaign used seemingly benign SKILL.md instructions to trick models/users into installing a fake prerequisite (“OpenClawCLI”) from an external site; if followed, the workflow fetched and executed a Base64-encoded command that dropped a Mach-O universal binary (Intel and Apple Silicon). Trend Micro reported 39 malicious skills uploaded across repositories and stated that more than 2,200 malicious skills were ultimately found on GitHub, with AMOS targeting credentials, browser data, crypto wallets, Telegram data, VPN profiles, Apple Keychain items, and common user folders—underscoring that AI-agent ecosystems are becoming a practical malware delivery and data-theft channel.

Share:
Malicious AI Agent Skills Abused for Crypto Theft and macOS AMOS Delivery
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
May 5, 20262mo ago

Zscaler details DeepSeek-Claw skill delivering Remcos RAT and GhostLoader

Zscaler ThreatLabz reported that a malicious OpenClaw skill named "DeepSeek-Claw" impersonated a DeepSeek integration and delivered two malware chains. On Windows it installed Remcos RAT via an MSI and DLL sideloading with a signed GoToMeeting executable, while manual install paths triggered the cross-platform GhostLoader stealer targeting developer credentials, wallets, SSH keys, and cloud tokens.

OpenClaw Skill Distributes Remcos & GhostLoader | ThreatLabz
Apr 30, 20262mo ago

Acronis links 575+ malicious ClawHub skills to 13 developer accounts

Acronis Threat Research Unit reported that ClawHub was hosting more than 575 malicious OpenClaw skills published by 13 developer accounts, with most attributed to the aliases hightower6eu and sakaen736jih. The report said the skills targeted Windows and macOS users with AMOS Stealer, trojans, and a cryptominer, using social engineering, hidden dependencies, password-protected archives, encoded commands, and prompt-injection-style abuse.

Poisoning the well: AI supply chain attacks on Hugging Face and OpenClaw
Apr 29, 20262mo ago

Researcher identifies 30 ClawHub skills in "ClawSwarm" crypto-swarm campaign

Manifold researcher Ax Sharma reported that 30 ClawHub skills published by the user "imaflytok" silently enrolled installed AI agents into a cryptocurrency-oriented swarm via onlyflies.buzz. The skills abused normal instruction files and skill functionality to make agents disclose metadata, store credentials locally, periodically check in, and in some cases generate Hedera wallets and submit private keys without user consent.

30 ClawHub skills secretly turn AI agents into crypto swarm • The Register
Mar 24, 20263mo ago

Silverfort discloses ClawHub ranking-manipulation vulnerability

Silverfort reported a ClawHub vulnerability that could allow attackers to manipulate marketplace rankings and push a malicious skill to the number-one position. The disclosure introduced a new platform-level weakness that could amplify discovery and distribution of malicious skills beyond the previously documented ClawHavoc campaign tactics.

ClawHub vulnerability puts malicious skill at #1 | Silverfort
Mar 3, 20264mo ago

Researchers observe live AMOS operator harden C2 during March campaign

In March 2026, Breakglass Intelligence analyzed an active fake OpenClaw skill campaign delivering Atomic macOS Stealer and observed the operator replace the original dropper with a revised version that changed encryption, added anti-VM checks, and rotated C2 credentials. After researchers authenticated to the live C2 and mapped its protocol, the operator hardened the infrastructure within 29 minutes by removing console endpoints and blocking uploads while keeping token validation active.

Fake "OpenClaw Skill" AMOS Stealer: Cracking Two Encryption Schemes, Authenticating Against a Live C2, and Mapping an Active macOS Infostealer Campaign - Breakglass Intelligence - Breakglass Intelligence
Feb 27, 20264mo ago

PolySwarm publishes ClawHavoc campaign details and follow-on tactics

PolySwarm publicly detailed the ClawHavoc campaign, including AMOS delivery on macOS, theft of OpenClaw bot configuration secrets, webhook-based exfiltration, and reverse shells. The report also described follow-on comment-based social engineering on popular Skills that redirected users to attacker infrastructure such as 91.92.242[.]30.

Feb 25, 20264mo ago

Researchers uncover bob-p2p ClawHub skill used in crypto scam

Staiker researchers identified a malicious ClawHub skill called "bob-p2p" that was promoted on Moltbook as a decentralized API marketplace. Once installed, it caused agents to store Solana wallet private keys in plaintext and buy worthless $BOB tokens while sending payments to attacker-controlled infrastructure.

Feb 24, 20264mo ago

Attackers shift AMOS delivery to malicious OpenClaw skills

Trend Micro reported a new Atomic macOS Stealer variant distributed through malicious OpenClaw skills uploaded to ClawHub, SkillsMP, and GitHub. The infection chain used benign-looking SKILL.md files to direct users to install a fake prerequisite and then execute a payload that could trigger a fake password prompt to capture the macOS system password.

Feb 15, 20264mo ago

ClawHavoc campaign expands across ClawHub as marketplace grows

By mid-February 2026, researchers said the campaign had grown to 824 identified malicious Skills, with more than 900 malicious Skills used overall as ClawHub exceeded 10,700 listed Skills. The operation targeted both Windows and macOS users with staged payload delivery, credential theft, reverse shells, and secret exfiltration.

Feb 1, 20265mo ago

Researchers identify 341 malicious ClawHub skills in ClawHavoc campaign

PolySwarm reported that the ClawHavoc supply-chain poisoning campaign had already uploaded 341 malicious Skills to ClawHub by February 1, 2026. The skills used convincing documentation and fake setup prerequisites to trick OpenClaw users into executing malicious payloads.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

75 LINKEDOpen in app
Affected products
29 linked
OpenclawWindows DefenderGithubTelegramNpmMacosDash CoreVirustotalWindows InstallerWindowsWhatsappParallels DesktopTrelloClaude CodeSafariPowershellBrave BrowserFirefoxMacosLedger LiveOpenvpnLinkedinGithubArcOperaGoogle SearchDeepseekN8nLinux
Organizations
33 linked
CloudflareClawHubHugging FaceAcronisGitHubTelegramThe RegisterLogmeinManifoldTrend MicroPolySwarmKoi SecurityZscalerMediafireVirustotalSecurityWeekAnthropicAppleVercelTrezorLedgerCogent CommunicationsHelp Net SecurityMoltbookOpenclawStaikerGuruculHello Internet CorpBreakglass IntelligenceSlim ChickensMcAlister's DeliSwigNoodles & Company
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Malicious AI Agent Skills Abused for Crypto Theft and macOS AMOS Delivery | Mallory