Threat · curated 16 Jul 2026
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
First reported paloaltonetworks.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
OpenClaw's skill marketplace shows that AI-agent extension ecosystems have become a software supply-chain attack surface, letting adversaries ship malware and stealers directly into agent runtimes that users implicitly trust.
Unit 42 describes an emerging AI supply-chain threat in which malicious "skills" published to the OpenClaw agent skill marketplace act as a distribution channel for malware and data theft. Corroborating research from Trend Micro (Atomic macOS Stealer delivery), Bitdefender, Koi.ai (341 malicious ClawedBot skills) and JFrog documents how attackers hide payloads inside agent skills users install to extend AI-agent capabilities.