OpenSourceMalware: 230+ malicious OpenClaw extensions, posing as crypto trading automation tools to steal user info, were uploaded to ClawHub since January 27
Or is that Moltbot, or Clawdbot? I can't keep up. … Security researchers are warning that the growing ecosystem around 'OpenClaw …
Context & Ripple Effects
The incident emerged while the project was still settling on the OpenClaw name after two rapid renames. That churn can make it harder for users to distinguish official tooling from marketplace uploads, particularly when extensions borrow the language of crypto automation.
The later decision to add VirusTotal scanning for every ClawHub skill shows the marketplace moved from an open distribution surface toward a security-screened one. The reported malicious uploads explain why that governance layer matters early in an agent ecosystem's growth.
First-order effects
- Users who installed the crypto-themed extensions faced potential theft of their information; ClawHub users must treat affected skills as untrusted until reviewed or removed.
- ClawHub and extension maintainers face an immediate trust and moderation problem: malicious listings can make legitimate automation tools harder for users to evaluate.
Second-order effects
- Marketplace-wide scanning becomes a practical response to the compromise pattern, as reflected in ClawHub's subsequent VirusTotal integration.
- Crypto-branded agent extensions are likely to receive heavier scrutiny from users and marketplace operators, raising the burden on legitimate developers to demonstrate provenance and safety.
Third-order effects
- If agent marketplaces continue to distribute code with access to user data, security review and provenance signals may become core marketplace infrastructure rather than optional add-ons.
- The episode points to a broader tension in open agent ecosystems: rapid extension growth expands utility, but also creates a supply-chain security problem that centralized screening can mitigate without fully eliminating.
The trend: AI-agent extension marketplaces are evolving from lightly governed code catalogs toward security-mediated distribution channels as malicious packages target early users.