News · curated 27 Jun 2026
More Malicious OpenClaw Skills Threaten AI Supply Chain
First reported darkreading.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Malicious skills distributed through an AI agent marketplace can deliver infostealers and compromise downstream users, highlighting the AI supply-chain attack surface.
OpenClaw reportedly removed five malicious packages from its ClawHub skills marketplace that bypassed security checks while containing infostealers and other threats, posing an AI agent supply-chain risk.