The OpenClaw ClawHub marketplace has identified 1,184 malicious tools designed to steal SSH keys, crypto wallets, and browser passwords, as well as open reverse shells. A single attacker is responsible for uploading 677 of these packages. The most downloaded tool contains nine vulnerabilities and has been accessed thousands of times. Users are advised to use AI tools in isolated environments due to the potential risks posed by many OpenClaw skills.
In related security news, Moonwell recently suffered a $1.78 million hack, with the vulnerability traced back to code from Co-Authored-By: Claude Opus 4.6. This incident highlights that in Web3 security, threats extend beyond smart contracts to other areas of the ecosystem.
ClawHub Market Flags Over 1,180 Malicious Tools Targeting Crypto Security
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
