Monday, February 9, 2026
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks

by DigestWire member
February 9, 2026
in Blockchain, Crypto Market, Cryptocurrency
0
OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Makina Finance hack

The post OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks appeared first on Coinpedia Fintech News

OpenClaw’s fast-growing plugin store, ClawHub, is under security spotlight after blockchain security firm SlowMist uncovered a large batch of malicious skills on the platform. 

The finding points to weak review checks that allowed hidden, harmful code to spread through developer tools.

OpenClaw ClawHub Plugin Faces Supply Chain Attack Risk

SlowMist revealed that OpenClaw’s official plugin hub, known as ClawHub, has become a new target for supply chain-style attacks. The platform recently gained rapid popularity among AI agent developers, but its plugin screening process did not keep pace with growth.

Because plugin reviews were not strict enough, attackers were able to publish many dangerous skills that looked useful on the surface but carried hidden risks.

SlowMist teams say this type of attack is especially risky because developers often trust official plugin centers and follow installation steps without deep inspection.

🚨 Threat Intelligence | Analysis of ClawHub Malicious Skills Poisoning

As the #OpenClaw AI agent ecosystem rapidly grows, SlowMist has observed ClawHub becoming a new target for large-scale supply chain attacks. Due to insufficient review mechanisms, hundreds of malicious… pic.twitter.com/xfzo4AhTdb

— SlowMist (@SlowMist_Team) February 9, 2026

341 Malicious Plugins Expose

During a broad scan of the ClawHub ecosystem, security researchers found a high number of unsafe plugins. A separate scan by Koi Security reviewed 2,857 skills and flagged 341 as malicious.

SlowMist’s deeper tracking reviewed more than 400 threat indicators and found clear patterns, many of the bad plugins connected back to the same small group of domains and server addresses. 

OpenClaw ClawHub plugin

However, Slowmist says that this suggests an organized and repeated attack effort, not random uploads.

How the Attack Actually Works?

According to the researchers, the main weakness comes from how OpenClaw skills are built. Many rely on instruction files that users run directly during setup. Attackers abused this by placing hidden download-and-run commands inside those instructions.

In many cases, the first attackers used coded messages to hide their real commands. When the code is decoded and run, it secretly downloads another program from an outside server. Secondly, that program then carries out the actual attack.

This two-step method helps attackers avoid early detection and lets them change the harmful program anytime without updating the visible plugin page.

Malicious Domain Analysis

SlowMist said its review of hundreds of threat indicators showed many of these plugins connected to the same small set of domains and IP addresses, 91.92.242.30. This suggests a planned, group-driven campaign rather than random one-off attacks.

Security teams are now warning OpenClaw users to double-check skill instructions and avoid running unknown command steps until stronger review controls are in place.

Read Entire Article
Tags: BlockchainCoin SurgesCoinPedia
Share30Tweet19
Next Post
Binance SAFU Fund Adds $300M in Bitcoin

Binance SAFU Fund Adds $300M in Bitcoin

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

Hilary Duff Relies on This $29 Bronzing Cream for a Fuss-Free Glow

Louisiana All-Girls Catholic School Teacher Arrested for Abusing Student

Turning Point USA All-American Halftime Show Announces Major Change

Hailey Bieber Wows in Dramatic Fur Coat at Super Bowl LX With Justin Bieber

Patriots WAG Ann Michael Elevates Gameday Look With $900 Pants and Chanel Bag

Jay-Z, Daughter Blue Ivy and More Stars Have the Best Time at Super Bowl LX

Trending

Binance SAFU Fund Adds $300M in Bitcoin
Blockchain

Binance SAFU Fund Adds $300M in Bitcoin

by DigestWire member
February 9, 2026
0

The post Binance SAFU Fund Adds $300M in Bitcoin appeared first on Coinpedia Fintech News Binance’s Secure...

OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks

OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks

February 9, 2026
Italy captain Wayne Madsen injures shoulder in T20 World Cup opener

Italy captain Wayne Madsen injures shoulder in T20 World Cup opener

February 9, 2026
Hilary Duff Relies on This $29 Bronzing Cream for a Fuss-Free Glow

Hilary Duff Relies on This $29 Bronzing Cream for a Fuss-Free Glow

February 9, 2026
Louisiana All-Girls Catholic School Teacher Arrested for Abusing Student

Louisiana All-Girls Catholic School Teacher Arrested for Abusing Student

February 9, 2026
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Binance SAFU Fund Adds $300M in Bitcoin February 9, 2026
  • OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks February 9, 2026
  • Italy captain Wayne Madsen injures shoulder in T20 World Cup opener February 9, 2026

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.