Fetching from the wire…
Public story · 2026-03-16 · source-backed
The first real supply chain attack on the agent instruction layer landed this week, and it's worse than the early reports suggested.
A campaign dubbed ClawHavoc planted 1,184 malicious skills in ClawHub — OpenClaw's official skill marketplace — by embedding adversarial instructions directly in SKILL.md files. Not in code. Not in dependencies. In the instruction files that agents treat as trusted configuration. One account uploaded 677 packages in a single automated blitz. Payloads include an AMOS-variant macOS stealer targeting browser credentials, keychains, SSH keys, and crypto wallets, plus hidden reverse shells and credential exfiltration routines. CyberSecurityNews
The attack class is novel because it weaponizes the trust relationship between agents and their skill definitions. When your agent reads a SKILL.md, it processes the content as authoritative instructions — not as untrusted input. ClawHavoc exploits exactly this assumption. Roughly 20% of the ClawHub registry is now confirmed malicious, with 300,000+ users exposed.
But ClawHavoc isn't operating in isolation. Independent researchers documented a separate OpenClaw attack chain where adversarial instructions embedded in a fetched web page cause the agent to generate an attacker-controlled URL, and Telegram/Discord link previews silently transmit sensitive data without any user click. The Hacker News Meanwhile, Bitdefender published a technical advisory identifying over 42,000 internet-exposed OpenClaw deployments, most running without authentication, with access tokens visible in query parameters and shared global context exposing secrets across users. Bitdefender
Three attack vectors — poisoned skills supply chain, SSRF-via-link-preview exfiltration, and unauthenticated remote control — converging on the same platform in the same week. If you're running OpenClaw in any production context, audit your skill sources today, lock down authentication, and treat every MCP tool definition as untrusted code.
Each link below shares sources, entities, or timing with this story.
Snyk supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Snyk supports MCP); both cover ClawHub, Malicious Skills, OpenClaw, SSH; reported by the same outlet (thehackernews.com).
Cloudflare supports MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Cloudflare supports MCP); both cover MCP, SSRF, The Hacker News, URL; overlapping topics (agent, code, instruction, user).
Snyk supports MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Snyk supports MCP); both cover ClawHavoc, ClawHub, OpenClaw; overlapping topics (attack, chain, clawhavoc, clawhub, maliciou).
Microsoft supports MCP / Shared entities / Same source domain / Shared topic / What happened next / Tension
Linked by a graph relationship (Microsoft supports MCP); both cover MCP, SSRF, The Hacker News; reported by the same outlet (thehackernews.com).
MCP uses Docker / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (MCP uses Docker); both cover OpenClaw, SSRF, The Hacker News; reported by the same outlet (thehackernews.com).
OpenClaw released ClawHub / Shared entities / Same source domain / Shared topic / What happened next / Tension
Linked by a graph relationship (OpenClaw released ClawHub); both cover ClawHavoc, ClawHub, The Hacker News; reported by the same outlet (thehackernews.com).
Microsoft supports MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Microsoft supports MCP); both cover ClawHub, MCP, Meanwhile; overlapping topics (agent, attack, chain, clawhub, code).
Anthropic released MCP / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (Anthropic released MCP); both cover MCP, Skill, SSRF; overlapping topics (agent, code, context, skill).