The Wire.Tracking threats to Agents 312 raw → 45 curated · updated 27 Jun 2026

Incident · curated 27 Jun 2026

More Malicious OpenClaw Skills Threaten AI Supply Chain

First reported 24 Jun 2026 · 2d ago

Coverage timeline

24 Jun 2026

Single-source incident — first reported, latest, and curated coincide.

Malicious skills distributed through an AI agent marketplace can deliver infostealers and compromise downstream users, highlighting the AI supply-chain attack surface.

OpenClaw reportedly removed five malicious packages from its ClawHub skills marketplace that bypassed security checks while containing infostealers and other threats, posing an AI agent supply-chain risk.

Why it matters

Malicious skills distributed through an AI agent marketplace can deliver infostealers and compromise downstream users, highlighting the AI supply-chain attack surface.

Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS