Security · 2h ago
Malicious OpenClaw Skills Bypass Security Checks on ClawHub
OpenClaw removed five malicious packages from its ClawHub marketplace that evaded security checks and contained infostealers. The packages threatened the AI supply chain by embedding malware in seemingly legitimate skills. This incident highlights vulnerabilities in AI platform security measures.
Meridian48 take
The breach underscores that AI marketplaces remain a weak link in the software supply chain, despite security claims.
ai-supply-chainmalware