ClawHub Marketplace Skills Expose OpenClaw AI Agents to RCE, Data Theft, and Supply-Chain Backdoors (CVE-2026-25253) — Threadlinqs Intelligence
As of 2026-07-11, ClawHub Marketplace Skills Expose OpenClaw AI Agents to RCE, Data Theft, and Supply-Chain Backdoors (CVE-2026-25253) is a high-severity supply chain threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1212 · Severity: HIGH · CVSS: 8.8 · Status: ACTIVE · Category: SUPPLY_CHAIN
ClawHub, the official skill marketplace for the open-source OpenClaw AI agent platform, grew from under 2,000 to over 50,000 skills between January and April 2026 with minimal security review,
OpenClaw is an open-source AI agent framework that grants installed "skills" full system permissions — file read/write, network access, and shell command execution — immediately upon installation, with no sandboxing or per-permission scoping. ClawHub, its official skill marketplace, scaled from fewer than 2,000 skills in January 2026 to over 50,000 by April 2026, a 25x expansion in under 90 days, dramatically outpacing any vetting capacity.
This explosive, unvetted growth produced four distinct but related security failures documented across independent researchers between February and June 2026:
1. **ClawHavoc supply-chain campaign**: Beginning around January 2026, threat actors compromised or created developer accounts on ClawHub to publish malicious skills. Koi Security's Oren Yomtov first disclosed 341 malicious skills out of 2,857 scanned on February 1, 2026; a follow-up scan on February 16 found 824 malicious skills in a registry that had grown to 10,700+; Antiy Labs ultimately catalogued 1,184 malicious skills published historically to ClawHub via 12 compromised developer accounts, resulting in 247,000 confirmed installations and $2.3 million in stolen cryptocurrency. Payloads used typosquatted skill names ("Google Assistant Pro," "YouTube Summarize Pro," wallet/Polymarket/YouTube utilities) to deliver the Atomic macOS Stealer (AMOS) trojan, embedded in shell scripts and later pivoted to skill-page comments disguised as "update service" instructions after SKILL.md-focused scanning caught the initial vector.
2. **CVE-2026-25253 — one-click RCE via auth-token exfiltration**: OpenClaw's Control UI (affecting all versions before 2026.1.29) reads a `gatewayUrl` value from a query string and automatically establishes a WebSocket connection without user confirmation, transmitting the operator's authentication token to whatever host the URL specifies. Because OpenClaw operates with full file/shell access, token theft grants an attacker complete control of the victim's machine with a single malicious link click. Public disclosure was February 3, 2026; contemporaneous internet-wide scanning found over 40,000 exposed OpenClaw instances, 63% assessed as remotely exploitable. The vendor's initial fix (2026.1.29) added a confirmation prompt when gatewayUrl changes.
3. **Pickle-deserialization RCE backdoor**: A skill masquerading as a "distributed state recovery tool," complete with legitimate-looking architecture documentation, fetched a remote payload from attacker C2, decoded it through a chained 12-method encoding scheme (Base64, ROT13, Morse, and others), and executed it via unsafe Python `pickle.loads()` deserialization. Tencent's Zhuque Lab AIG platform flagged the combination of remote fetch, chained encoding, and unsafe deserialization as the detection signature; the skill's declared networking/Python-runtime permissions appeared superficially legitimate for its stated purpose.
4. **Download-ranking manipulation → autonomous auto-install**: Silverfort researchers found an unauthenticated, unrate-limited public RPC endpoint (`download.increment`) that let any attacker with a skill ID and deployment URL arbitrarily inflate a skill's download count. Using a proof-of-concept "Outlook Graph Integration" skill with a hidden data-exfiltration payload (collecting the victim's username and FQDN to an attacker-controlled server), the researchers drove the skill to the #1 ranking in its category, producing 3,900 autonomous executions within 6 days across 50+ cities, including at several public companies — because OpenClaw agents autonomously prioritize installing the highest-ranked skill when selecting tools. Reported March 16, 2026; ClawHub shipped a fix within ~24 hours.
Broader corpus analysis by Tencent Zhuque Lab (scanning ~50,000 skills) found 74.6% declare network-request permissions and roughly 25% have file read/write capability, with 246,378 distinct external URLs (29,196 unique domains) referenced across skill code, sev
Weaknesses (CWE)
CWE-669, CWE-502, CWE-306
Target sectors: technology, cryptocurrency-finance, general-consumer, public-companies
Target regions: Global
Related threats
- OpenClaw / ClawHub AI Skill Marketplace Supply-Chain Compromise — Malicious Skills cluw, AMOS, omnicogg, money-radar, letssendit
- Malicious ClawHub Skills Threaten OpenClaw AI Agent Supply Chain (AMOS, cluw, Solana Front-Running)
- HalluSquatting: AI Coding Agents Hallucinate Predictable Fake Package/Repo/Skill Names, Enabling Supply-Chain Squatting Attacks
- ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering Attacks
- AI Supply Chain Abuse — 575 Trojanized OpenClaw/ClawHub Skills + Hugging Face Malware Staging (Acronis TRU)
- ClickFix / KongTuke Clipboard-Hijacking Social-Engineering Technique (MITRE T1204.004) — Fake-CAPTCHA Lures Delivering Infostealers, RATs, and Ransomware
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, CVE-2026-25253, T1195, T1566, T1199, T1203, T1059, T1059.006, T1059.004, T1204.001, T1211, T1547.013