The OpenClaw ClawHub marketplace has identified 1,184 malicious tools designed to steal SSH keys, crypto wallets, and browser passwords, as well as open reverse shells. A single attacker is responsible for uploading 677 of these packages. The most downloaded tool contains nine vulnerabilities and has been accessed thousands of times. Users are advised to use AI tools in isolated environments due to the potential risks posed by many OpenClaw skills. In related security news, Moonwell recently suffered a $1.78 million hack, with the vulnerability traced back to code from Co-Authored-By: Claude Opus 4.6. This incident highlights that in Web3 security, threats extend beyond smart contracts to other areas of the ecosystem.