ClawHavoc malicious agent skills
Palo Alto Networks Unit 42 documents ClawHavoc as an early ClawHub malicious-skill campaign and directly preserves the original 341-skill disclosure; its current research also documents May 17 skills using the same ClawHavoc delivery pattern with fresh infrastructure.
Also tracked as ClawHavoc
- First observed
- Feb 1, 2026
- Last observed
- May 17, 2026
- Last reviewed
- Sep 8, 2026
- Tracking ended
- Sep 8, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
Current Unit 42 research directly preserves the ClawHavoc identity and original 341-skill disclosure. The former Koi research URL now redirects, and the directly reviewed current primary evidence does not preserve the old 824 snapshot, so HOL no longer publishes that bounded update. Unit 42 says early campaign skills were removed or marked malicious and documents later structurally identical activity; this record does not claim a complete current marketplace inventory or victim count.
- Do not interpret this campaign record as a claim that Guard blocks every malicious skill. Current OpenClaw coverage is partial and does not universally mediate arbitrary skill instructions, manual or out-of-band execution, or malware that already executed.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
Not covered, or partially covered
partial
Current HOL Guard documentation explicitly detects OpenClaw workspace, user, and OpenClaw-owned skills. Shared skill protection flags package-manager install instructions inside SKILL.md before skill execution, and managed OpenClaw MCP package-manager calls route through Guard’s supply-chain evaluator. The OpenClaw protection contract is not universal interception of arbitrary skill instructions, manual or out-of-band execution, or malware that already executed.
- Recipe available
Treat new or changed agent skills and instruction artifacts as untrusted until their contents, provenance, and requested capabilities are reviewed.
This policy reduces exposure on supported artifact and action surfaces; it cannot make arbitrary third-party instructions safe.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- Disclosure
Current Unit 42 research identifies Koi Security’s early-February ClawHavoc disclosure as documenting 341 malicious skills.
- Update
Unit 42 observed newly published malicious skills using a delivery mechanism structurally identical to the earlier ClawHavoc campaigns, with fresh backend infrastructure.
- Correction
Primary evidence migrated to current Unit 42 research after the former Koi article URL stopped serving the historical report. The unsupported 824 snapshot was removed; Snyk remains contextual research.
Publication clock: 4547.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
reviewed malicious skill setClawHubskill
Sources
Every claim on this record is traceable to the sources below.
Record HGTC-2026-CLAWHAVOC