News View Non-AMP

OpenClaw ClawHub Under Attack: 341 Malicious Plugins Expose Supply Chain Risks

Published by
Rizwan Ansari and Sohrab Khawas

OpenClaw’s fast-growing plugin store, ClawHub, is under security spotlight after blockchain security firm SlowMist uncovered a large batch of malicious skills on the platform. 

The finding points to weak review checks that allowed hidden, harmful code to spread through developer tools.

OpenClaw ClawHub Plugin Faces Supply Chain Attack Risk

SlowMist revealed that OpenClaw’s official plugin hub, known as ClawHub, has become a new target for supply chain-style attacks. The platform recently gained rapid popularity among AI agent developers, but its plugin screening process did not keep pace with growth.

Because plugin reviews were not strict enough, attackers were able to publish many dangerous skills that looked useful on the surface but carried hidden risks.

SlowMist teams say this type of attack is especially risky because developers often trust official plugin centers and follow installation steps without deep inspection.

341 Malicious Plugins Expose

During a broad scan of the ClawHub ecosystem, security researchers found a high number of unsafe plugins. A separate scan by Koi Security reviewed 2,857 skills and flagged 341 as malicious.

SlowMist’s deeper tracking reviewed more than 400 threat indicators and found clear patterns, many of the bad plugins connected back to the same small group of domains and server addresses. 

However, Slowmist says that this suggests an organized and repeated attack effort, not random uploads.

How the Attack Actually Works?

According to the researchers, the main weakness comes from how OpenClaw skills are built. Many rely on instruction files that users run directly during setup. Attackers abused this by placing hidden download-and-run commands inside those instructions.

In many cases, the first attackers used coded messages to hide their real commands. When the code is decoded and run, it secretly downloads another program from an outside server. Secondly, that program then carries out the actual attack.

This two-step method helps attackers avoid early detection and lets them change the harmful program anytime without updating the visible plugin page.

Malicious Domain Analysis

SlowMist said its review of hundreds of threat indicators showed many of these plugins connected to the same small set of domains and IP addresses, 91.92.242.30. This suggests a planned, group-driven campaign rather than random one-off attacks.

Security teams are now warning OpenClaw users to double-check skill instructions and avoid running unknown command steps until stronger review controls are in place.

FAQs

What is the OpenClaw ClawHub security issue about?

OpenClaw’s ClawHub hosted malicious plugins that slipped through weak reviews, exposing developers to hidden code and supply chain-style attacks.

How many malicious plugins were found on ClawHub?

Security scans flagged 341 malicious plugins out of 2,857 reviewed, indicating a large and coordinated threat inside the ClawHub ecosystem.

What should OpenClaw users do to stay safe right now?

Avoid running unknown setup commands, review instructions carefully, and limit plugin installs until stronger security checks are enforced.

Trust with CoinPedia:

CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.

Investment Disclaimer:

All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.

Sponsored and Advertisements:

Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.

Rizwan Ansari and Sohrab Khawas

Rizwan is an experienced Crypto journalist with almost half a decade of experience covering everything related to the growing crypto industry — from price analysis to blockchain disruption. During this period, he’s authored more than 3,000 news articles for Coinpedia News.

Recent Posts

Morpho Whale Accumulation Grows, But Price Remains Range-Bound—Here’s What It Means

Morpho's price has maintained significant strength since the start of 2026, which has kept the…

July 26, 2026

Zcash (ZEC) Price Nears Major Breakout as $500 Liquidity Zone Comes Back Into Focus

After experiencing a significant sell-off, the bulls are trying hard to initiate a strong rebound…

July 26, 2026

Memecoin Mania Returns? PEPE, SHIB, and BOME Flash Bullish Breakout Signals

The memecoin sector is beginning to show signs of renewed strength after spending months in…

July 26, 2026

Top Cryptos Other Than Bitcoin and Ethereum Poised to Benefit From the CLARITY Act

The upcoming CLARITY Act is widely expected to reshape the U.S. crypto market by providing…

July 26, 2026

Dogecoin Price Rebounds as Shiba Inu Gains Strength—Can DOGE Rally Higher This Month?

After consolidating within a pre-defined range, the Dogecoin price is showing early signs of recovery.…

July 26, 2026

Avalanche Price at a Crossroads: Short-Term Breakout Awaits Weekly Confirmation-What’s Next?

Avalanche (AVAX) price hovered near $6.65 after climbing more than 3% this week, recovering from…

July 26, 2026