high severityConfidence highHistorical record

ClawHavoc malicious agent skills

Palo Alto Networks Unit 42 documents ClawHavoc as an early ClawHub malicious-skill campaign and directly preserves the original 341-skill disclosure; its current research also documents May 17 skills using the same ClawHavoc delivery pattern with fresh infrastructure.

Also tracked as ClawHavoc

First observed
Feb 1, 2026
Last observed
May 17, 2026
Last reviewed
Sep 8, 2026
Tracking ended
Sep 8, 2026

Uncertainty and limitations

Read the evidence limits before acting on this record.

Current Unit 42 research directly preserves the ClawHavoc identity and original 341-skill disclosure. The former Koi research URL now redirects, and the directly reviewed current primary evidence does not preserve the old 824 snapshot, so HOL no longer publishes that bounded update. Unit 42 says early campaign skills were removed or marked malicious and documents later structurally identical activity; this record does not claim a complete current marketplace inventory or victim count.

  • Do not interpret this campaign record as a claim that Guard blocks every malicious skill. Current OpenClaw coverage is partial and does not universally mediate arbitrary skill instructions, manual or out-of-band execution, or malware that already executed.

Guard coverage and policy

What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.

Not covered, or partially covered

  • partial

    Current HOL Guard documentation explicitly detects OpenClaw workspace, user, and OpenClaw-owned skills. Shared skill protection flags package-manager install instructions inside SKILL.md before skill execution, and managed OpenClaw MCP package-manager calls route through Guard’s supply-chain evaluator. The OpenClaw protection contract is not universal interception of arbitrary skill instructions, manual or out-of-band execution, or malware that already executed.

  • Recipe available

    Treat new or changed agent skills and instruction artifacts as untrusted until their contents, provenance, and requested capabilities are reviewed.

    This policy reduces exposure on supported artifact and action surfaces; it cannot make arbitrary third-party instructions safe.

Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.

Timeline

Reviewed events, oldest first, each tied to a verified source.

  1. Disclosure

    Current Unit 42 research identifies Koi Security’s early-February ClawHavoc disclosure as documenting 341 malicious skills.

  2. Update

    Unit 42 observed newly published malicious skills using a delivery mechanism structurally identical to the earlier ClawHavoc campaigns, with fresh backend infrastructure.

  3. Correction

    Primary evidence migrated to current Unit 42 research after the former Koi article URL stopped serving the historical report. The unsupported 824 snapshot was removed; Snyk remains contextual research.

Publication clock: 4547.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Reviewed artifacts

The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.

  • reviewed malicious skill setClawHubskill

Sources

Every claim on this record is traceable to the sources below.

Reviewed in full by HOL Guard Research.

Published
Last full review
Last modified

Report a correction

Record HGTC-2026-CLAWHAVOC