Threat Intelligence | Analysis of ClawHub Malicious Skills Poisoning
Background
Recently, the open-source AI agent project OpenClaw has unexpectedly gained popularity, and its official plugin hub, ClawHub, has rapidly attracted a large number of developers. The SlowMist security team has observed that ClawHub is gradually becoming a new target for attackers conducting supply chain poisoning attacks. Due to the platform’s lack of a comprehensive and strict review mechanism, a significant number of malicious skills have already infiltrated the hub and are being used to distribute malicious code or harmful content, posing potential security risks to developers and users.
Following the exposure of the incident, the SlowMist security team promptly initiated an in-depth analysis, issued early warnings to clients via MistEye, and continues to track newly added malicious skills on ClawHub.
Within the OpenClaw ecosystem, what are commonly referred to as skills are more accurately defined as “skill folders” under the AgentSkills specification, with SKILL.md typically serving as the core file.
The primary risk of SKILL.md lies in the fact that it is not an auditable or reproducible build artifact within a code repository, but rather a set of operational instructions that users are likely to execute directly. In agent ecosystems, Markdown files often act as the “installation/initialization entry point,” causing text to shift from being mere “documentation” to becoming executable “instructions.” Attackers can simply disguise malicious commands as dependency installation or environment setup steps (such as curl | bash or Base64-decoded execution), thereby luring users into completing the execution chain and ultimately enabling payload deployment and data exfiltration.
According to a report by Koi Security, a scan of 2,857 skills identified 341 malicious skills, reflecting a typical pattern of supply chain poisoning in plugin/extension marketplaces.
Attack Technique Analysis
After consolidating the IOCs from more than 400 malicious skills, we found that many samples repeatedly point to a small number of fixed domains, or to multiple randomized paths hosted under the same IP address. Clear patterns of resource reuse and convergence were observed. This strongly suggests a group-based, large-scale attack operation, in which a large number of malicious skills share the same set of domains/IPs and employ largely identical attack techniques.
In terms of payload delivery, attackers frequently rely on public platforms as intermediate distribution channels, such as GitHub Releases and text-hosting services like glot.io. The malicious chains typically follow a classic “two-stage” loading mechanism: in the first stage, obfuscated commands are used to evade detection; in the second stage, high-risk payloads are dynamically fetched. This approach significantly reduces the exposure surface of the skill wrapper, allowing attackers to rapidly rotate backend resources.
In addition, the naming of these skills is relatively concentrated, mainly revolving around crypto assets, financial information, and scenarios such as “updates,” “security checks,” or “automation tools” — contexts that are more likely to lower user vigilance.
The poisoning chain can be summarized as follows:
1)A malicious skill disguises itself as “dependency installation / initialization” steps within SKILL.md;
2)The real commands are hidden using Base64 encoding or segmented scripts;
3)After decoding, a typical download-and-execute pattern is triggered (fetch via curl → execute via bash);
4)The first-stage payload then fetches the second-stage sample;
5)Finally, a small number of fixed IP addresses or domains are used for command-and-control consolidation and continuous updates.
Trojan Analysis
Taking the high-download “X (Twitter) Trends” skill as an example, its outward description appears completely normal and its usage instructions align with user expectations. However, it actually conceals a backdoor command encoded in Base64.
The attacker uses Base64 encoding to achieve “obfuscation at the readability level,” making the content of SKILL.md appear as if it is merely outputting configuration strings or installation information, thereby lowering the reader’s level of suspicion. At the same time, this technique helps evade some coarse, keyword-based detection mechanisms (such as directly matching curl | bash).
After decoding the Base64 command, it is essentially a typical “download-and-execute” instruction.
The first-stage sample serves only as an entry point, while the actual functionality is placed in the second-stage payload, allowing attackers to freely replace payloads and iterate rapidly without frequently modifying the skill wrapper.
Specifically, the command downloads and executes a program named q0c7ew2ro8l2cfqp from 91.92.242.30, which then proceeds to download and execute the second-stage sample dyrtvwjfveyxjf23.
This staged delivery approach is primarily intended to achieve “low-cost iteration and reduced exposure.” The skill wrapper (SKILL.md) can remain relatively stable and even appear to be a legitimate installation guide, while the real malicious capabilities are embedded in the second-stage payload. By simply swapping out the second-stage payload, attackers can quickly update functionality and evasion strategies, while also bypassing static text–based reviews and filtering.
Dynamic analysis shows that the second-stage sample disguises itself as a system dialog to phish for the user’s password. After verifying that the password is valid, it collects and archives local system information and documents in a temporary directory, and reads files from the Desktop, Documents, and Download directories.
When files such as .txt and .pdf are identified, the matched files along with host information are packaged into a ZIP archive and uploaded to a C2 endpoint (hxxps[:]//socifiapp.com/api/reports/upload).
Malicious Domain Analysis
According to queries on threat intelligence platforms, the malicious domain socifiapp[.]com was registered on July 14, 2025, and has already been flagged as malicious remote control (RAT) infrastructure.
The IP address 91.92.242.30 is reused across a large number of malicious skills. According to public threat intelligence, this IP is associated with historical infrastructure linked to Poseidon. The group’s commonly observed tactics include extortion following data theft.
MistEye Response
MistEye is a Web3-focused threat intelligence and dynamic security monitoring tool independently developed by SlowMist. It deeply integrates security monitoring and intelligence aggregation capabilities to provide users with real-time risk alerts and asset protection.
After confirming the characteristics of the malicious activity, the MistEye system triggered high-severity alerts at the earliest possible stage. This alert covered 472 malicious skills and their associated IOCs, and the relevant threat intelligence has been fully delivered to clients.
The adversarial dynamics within the skills ecosystem are still ongoing. MistEye will continue round-the-clock monitoring across major application marketplaces to ensure the earliest possible detection and identification of emerging malicious skills. Going forward, we will formally introduce dedicated monitoring rules tailored to skill mechanisms, providing customers with more durable and long-term security protection.
Summary
At its core, this incident highlights a supply chain risk driven by the combination of “ecosystem entry points + executable text instructions.” While skill wrappers can be endlessly rebranded or repackaged, attackers ultimately rely on a small set of reusable remote resources and execution endpoints. From a defensive perspective, focusing on signals such as “two-stage loading,” “highly reused infrastructure,” and “bare IP–based delivery points” is often more effective than taking down skills one by one. The IOCs listed below can be used for rapid blocking and threat hunting, but establishing long-term detection capabilities based on behavioral chains is strongly recommended.
Mitigation Recommendations
1. Do not treat the “installation steps” in SKILL.md as a trusted source; any command that requires copy-and-paste execution should be audited first.
2. Be alert to prompts that request system passwords, accessibility permissions, or system configuration changes, as these often represent escalation points for risk.
3. Prioritize obtaining dependencies and tools from official channels, and avoid executing installation scripts from unknown or unverified sources.
IOCs
Domain
socifiapp[.]com
rentry[.]co
install[.]app-distribution.net
URL
hxxp[:]//91.92.242.30/7buu24ly8m1tn8m4
hxxp[:]//91.92.242.30/x5ki60w1ih838sp7
hxxp[:]//91.92.242.30/528n21ktxu08pmer
hxxp[:]//91.92.242.30/66hfqv0uye23dkt2
hxxp[:]//91.92.242.30/6x8c0trkp4l9uugo
hxxp[:]//91.92.242.30/dx2w5j5bka6qkwxi
hxxp[:]//54.91.154.110:13338/
hxxp[:]//91.92.242.30/6wioz8285kcbax6v
hxxp[:]//91.92.242.30/1v07y9e1m6v7thl6
hxxp[:]//91.92.242.30/q0c7ew2ro8l2cfqp
hxxp[:]//91.92.242.30/dyrtvwjfveyxjf23
hxxps[:]//rentry.co/openclaw-core
hxxps[:]//glot.io/snippets/hfdxv8uyaf
hxxp[:]//92.92.242.30/7buu24ly8m1tn8m4
hxxp[:]//95.92.242.30/7buu24ly8m1tn8m4
hxxps[:]//install.app-distribution.net/setup/
hxxp[:]//11.92.242.30/7buu24ly8m1tn8m4
hxxp[:]//202.161.50.59/7buu24ly8m1tn8m4
hxxp[:]//96.92.242.30/7buu24ly8m1tn8m4
hxxps[:]//glot.io/snippets/hfd3x9ueu5
IP
91.92.242.30
104.18.38.233
95.92.242.30
54.91.154.110
92.92.242.30
11.92.242.30
202.161.50.59
96.92.242.30
file
filename: dyrtvwjfveyxjf23
SHA256: 30f97ae88f8861eeadeb54854d47078724e52e2ef36dd847180663b7f5763168
filename: 66hfqv0uye23dkt2
SHA256: 0e52566ccff4830e30ef45d2ad804eefba4ffe42062919398bf1334aab74dd65
filename: x5ki60w1ih838sp7
SHA256: 1e6d4b0538558429422b71d1f4d724c8ce31be92d299df33a8339e32316e2298
filename: dx2w5j5bka6qkwxi
SHA256: 998c38b430097479b015a68d9435dc5b98684119739572a4dff11e085881187e
filename: openclaw-agent.exe
SHA256: 17703b3d5e8e1fe69d6a6c78a240d8c84b32465fe62bed5610fb29335fe42283
About SlowMist
SlowMist is a threat intelligence firm focused on blockchain security, established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as HashKey Exchange, OSL, MEEX, BGE, BTCBOX, Bitget, BHEX.SG, OKX, Binance, HTX, Amber Group, Crypto.com, etc.
SlowMist offers a variety of services that include but are not limited to security audits, threat information, defense deployment, security consultants, and other security-related services. We also offer AML (Anti-money laundering) software, MistEye (Security Monitoring), SlowMist Hacked (Crypto hack archives), FireWall.x (Smart contract firewall) and other SaaS products. We have partnerships with domestic and international firms such as Akamai, BitDefender, RC², TianJi Partners, IPIP, etc. Our extensive work in cryptocurrency crime investigations has been cited by international organizations and government bodies, including the United Nations Security Council and the United Nations Office on Drugs and Crime.
By delivering a comprehensive security solution customized to individual projects, we can identify risks and prevent them from occurring. Our team was able to find and publish several high-risk blockchain security flaws. By doing so, we could spread awareness and raise the security standards in the blockchain ecosystem.
