New Wave of Malicious ClawHub Skills Delivers macOS Infostealers via curl-pipe-bash Droppers
OpenClaw users, this is a heads-up you actually need to read. Today, June 25, 2026, TechRadar reported that five new malicious skills on ClawHub have been identified and removed — the latest wave in an ongoing supply-chain attack campaign targeting OpenClaw’s skill marketplace. Two of the packages delivered macOS infostealers capable of exfiltrating credentials, crypto wallets, browser data, and your OpenClaw configuration files. This is directly relevant to you if you install skills from ClawHub. And frankly, most OpenClaw users do. ...