A recent report highlights a significant security threat involving the Skill 'What Would Elon Do,' which was once the top download on ClawHub. According to Foresight News, GoPlus monitoring has revealed that this Skill is actually a Trojan program. Attackers manipulated rankings and used bots to increase downloads, leading many users to install the malicious software.
Once installed, the Skill steals users' SSH keys, cryptocurrency wallet private keys, and browser cookies, establishing a reverse shell to the attackers' server. This has resulted in actual asset losses for users. The incident has uncovered a severe new supply chain attack vector within the Skill ecosystem. GoPlus advises users to cease running OpenClaw without protection.
Additionally, chiefofautism has disclosed that the ClawHub marketplace contains 1,184 malicious Skills, with a single attacker responsible for uploading 677 of these harmful packages.