Skip to main content
A menacing robot claw, representing OpenClaw AI, extends from a computer screen, holding a Trojan horse. [esecurityplanet.com

Editorial illustration for OpenClaw AI agent used to deliver Trojans via fake ClawHub skills

AI Assistant Backdoor Hack Exposes Viral Clawdbot Risks

OpenClaw AI agent used to deliver Trojans via fake ClawHub skills

Updated: 3 min read

The promise of an open ecosystem where AI agents can extend their capabilities at will has a dark underside, one that attackers just exploited with chilling precision. On ClawHub, the official skill marketplace for OpenClaw, someone uploaded more than 300 apparently clean skills that did exactly what they were asked, they just asked the agent to fetch a Trojan from elsewhere. The benign facade was perfect; the payloads were not.

Among them, the notorious macOS stealer Atomic Stealer. Now, OpenClaw founder Peter Steinberger has struck a rapid-response deal with VirusTotal, forcing every skill through an AI-powered sieve. The game just changed.

OpenClaw founder Peter Steinberger announced a partnership with VirusTotal in response to the attack. Every skill published on ClawHub is now automatically scanned using VirusTotal's AI-powered "Code Insight" feature (built on Google's Gemini), among other tools. The system analyzes what a skill actually does from a security standpoint, whether it downloads external files, accesses sensitive data, or manipulates the agent into unsafe behavior.

The response was swift, and the collaboration with VirusTotal is necessary, but it is also a patch, not a panacea. OpenClaw now scans every skill, yet the attackers’ playbook is proven: hide the payload, exploit trust, and let the agent do the dirty work. That single user who uploaded over 300 infected skills wasn’t an outlier; he was a signal.

As AI agents become our deputies in more domains, the attack surface metastasizes. Code scanning catches what is known, but creativity outruns curation. The real takeaway is uncomfortable: every platform that lets an AI agent execute third-party code is one clever bypass away from becoming a delivery network.

OpenClaw has closed this door. The next breach will find a window.

Common Questions Answered

How did attackers exploit the ClawdBot VS Code extension to deliver malware?

The malicious VS Code extension masqueraded as a legitimate AI coding assistant called 'ClawdBot Agent', which functioned as a real coding tool while silently deploying malware onto Windows machines. The extension was designed to automatically activate when VS Code starts, using a carefully crafted `initCore()` function that could download and run malicious payloads without user awareness.

What made the fake ClawdBot extension particularly dangerous?

The extension was exceptionally deceptive because it actually worked as a functional AI coding assistant, integrating with seven different AI providers like OpenAI, Anthropic, and Google. Its professional appearance, polished UI, and genuine functionality made it extremely convincing, allowing it to lull victims into a false sense of security while operating malware in the background.

Where did the malware's command-and-control (C2) traffic originate?

The investigation traced the malware's command-and-control traffic to a suspicious domain called darkgptprivate[.]com, which was hosted in the Seychelles. The attack chain involved downloading payloads disguised as common files like Lightshot.exe or an Electron bundle named Code.exe, with hardcoded references suggesting the attackers had evolved their payload over time.

LIVE03:21OpenAI's Miles Wang in Talks for USD 2B AI Drug Discovery Startup