Trending News

Global Games Show Riyadh Unveils Star-Studded Speaker Lineup of Gaming Legends and Industry Leaders

Global Blockchain Show Riyadh Unveils World-Class Speakers Redefining the Future of Web3 and Digital Assets

Global AI Show Riyadh Reveals a Powerhouse Speaker Lineup Shaping the Future of AI in the Middle East

Blockchain Futurist Conference Returns to Toronto for Its Ninth Year

Exito to Host 30th Cyber Security Summit Philippines 2026 in Manila

TAO Sees Mild Correction After Historic Surge Driven by NVIDIA Endorsement

Follow Us

Facebook Instagram X-twitter Telegram Linkedin Cmc Rss
NameCoinNews
  • News
    • Cryptocurrency
    • Crypto Exchange
    • Blockchain
    • Regulation
    • Crime
    • Web3
  • Markets
    • Price Predictions
    • Price Analysis
    • ETFs
  • Crypto Gambling
    • Best Crypto and Bitcoin Casinos
    • Best Crypto and Bitcoin Gambling Sites
    • Best Crypto No Deposit Bonuses
    • Best Dogecoin Gambling Sites
    • View More
  • Events
  • Presales
  • Blog
  • News
    • Cryptocurrency
    • Crypto Exchange
    • Blockchain
    • Regulation
    • Crime
    • Web3
  • Markets
    • Price Predictions
    • Price Analysis
    • ETFs
  • Crypto Gambling
    • Best Crypto and Bitcoin Casinos
    • Best Crypto and Bitcoin Gambling Sites
    • Best Crypto No Deposit Bonuses
    • Best Dogecoin Gambling Sites
    • View More
  • Events
  • Presales
  • Blog
× Global Blockchain Show
× Global Blockchain Show
NameCoinNews
  • News
    • Cryptocurrency
    • Crypto Exchange
    • Blockchain
    • Regulation
    • Crime
    • Web3
  • Markets
    • Price Predictions
    • Price Analysis
    • ETFs
  • Crypto Gambling
    • Best Crypto and Bitcoin Casinos
    • Best Crypto and Bitcoin Gambling Sites
    • Best Crypto No Deposit Bonuses
    • Best Dogecoin Gambling Sites
    • View More
  • Events
  • Presales
  • Blog
  • News
    • Cryptocurrency
    • Crypto Exchange
    • Blockchain
    • Regulation
    • Crime
    • Web3
  • Markets
    • Price Predictions
    • Price Analysis
    • ETFs
  • Crypto Gambling
    • Best Crypto and Bitcoin Casinos
    • Best Crypto and Bitcoin Gambling Sites
    • Best Crypto No Deposit Bonuses
    • Best Dogecoin Gambling Sites
    • View More
  • Events
  • Presales
  • Blog
Advertise
ClawHub Plugins Compromised in Major AI Supply Chain Attack

ClawHub Plugins Compromised in Major AI Supply Chain Attack

Written byHarsh Chauhan
Edited by Harsh Chauhan
February 9, 2026
in Artificial Intelligence News
Follow us on Google News Add as preferred source on Google

Key Highlights:

  • Malicious plugins were uploaded to ClawHub as reported today, February 9, 2026 by SlowMist.
  • Hackers hid the harmful commands inside normal-looking installation instructions.
  • SlowMist suggests auditing installation steps, blocking malicious servers, and enforcing strict plugin reviews.

Cybersecurity company SlowMist has issued a serious warning about a security problem in the fast-growing AI agent ecosystem. They found that ClawHub, the official plugin store for the popular open-source project OpenClaw, has been compromised.

🚨 Threat Intelligence | Analysis of ClawHub Malicious Skills Poisoning

As the #OpenClaw AI agent ecosystem rapidly grows, SlowMist has observed ClawHub becoming a new target for large-scale supply chain attacks. Due to insufficient review mechanisms, hundreds of malicious… pic.twitter.com/xfzo4AhTdb

— SlowMist (@SlowMist_Team) February 9, 2026

This happened because plugins on ClawHub were not properly reviewed and hundreds of plugins were uploaded. These plugins looked harmless and were presented as normal setup or helper tools but little did anyone know that they contained hidden malware.

In such situations, as soon as these plugins are installed, they secretly siphon data and the user has no clue about the same.

How the Attack Was Carried Out

It was SlowMist who found out about this by using their security software, which figured out something was wrong. What they found was a clever trick. It can be understood that the attackers had targeted the SKILL.md files, which are basically text files providing information on how to install a plugin. Instead of text, these files were also containing dubious commands. When users followed the steps, they unknowingly ran malware on their systems.

The harmful commands were made to look like normal setup tasks such as installing software dependencies, setting up the environment, and to hide what they were really doing, attackers made use of Base64 encoding to scramble the code, curl-to-bash scripts that download and run files instantly and two-step malware loaders that avoid easy detection.

Another security firm, Koi Security, scanned 2,857 plugins on the platform and confirmed that out of these many, 341 were malicious.

That’s a 12% of infection rate, which strongly suggests that this was not an accident, but a well-planned and coordinated attack.

Where the Malware Is Coming From

Security researchers found that over 400 malicious plugins were all connecting back to just a few suspicious websites and IP addresses. One of them, 91.92.242.30, has links to older cyber-crime and extortion groups. Another, socifiapp.com, was registered only recently and is being used as a remote control server for malware.

Many of these fake plugins were designed to look attractive to developers. They used themes like crypto and wallets, finance tools, software “updates”, security or system checks. These names made the plugins seem useful and safe.

A real example includes a plugin “X (Twitter) Trends” that looks safe but secretly installs malware that steals personals and work data.

The plugin looks the same on the surface, while the hidden malware keeps changing. This helps attackers avoid basic security checks.

What SlowMist Is Doing

SlowMist detected 472 malicious plugins early and is now monitoring plugin marketplaces 24/7 to stop future attacks. This is not a one-time problem. This acts as a big risk across the entire plugin ecosystem and the main danger comes from “instruction files that actually run harmful code”, not just bad plugins being taken down one by one.

Instead of only removing infected plugins, platforms and users need to watch for warning signs such as plugins that download more files in multiple steps, the same servers or IPs being used, commands that connect directly to raw IP addresses.

What You Should Do to Stay Safe

Make sure you check install instructions before running them. Never copy-paste commands without understanding them. One should remain cautious of sudden password or permission requests as there are usually the signs of an attack. One should only download tools from reliable and official sources and not from random scripts.

Also Read: Strategy Unveils Q4 2025 Results, Earns 22.8% in BTC Yield

Previous Post

South Korea’s FSS Unveils Plan Targeting Whale Manipulation and SNS

Next Post

China Limits U.S. Treasury Bank Purchases Amid Crypto Regulation Shifts

Harsh Chauhan

Harsh Chauhan

Harsh is a seasoned senior editor and editor at NameCoinNews. With a wealth of experience across various industries, he has extensively covered Crypto, Blockchain, Web3, NFT, and AI. Holding a Blockchain Foundation certification, Harsh consistently delivers timely updates and incisive analyses, capturing the essence of the crypto industry.

Global Blockchain Show
Global Games Show Banner
google news google news
Facebook Instagram X-twitter Telegram Linkedin Svgexport-4 Rss
NameCoinNews

NameCoinNews is your go-to platform for the latest cryptocurrency updates, market trends, and expert insights on Bitcoin, Ethereum, and beyond. We deliver in-depth price analysis, blockchain innovations, and regulatory news, empowering crypto enthusiasts and investors with reliable, real-time information.

News Beats

  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • NFT
  • Crime
  • Regulation

Insights

  • Price Prediction
  • Price Analysis
  • Crypto ETFs
  • Crypto Events
  • Crypto Presales
  • Crypto Glossary

Connect With Us

  • About Us
  • Advertise
  • Press Release
  • Contact Us
  • Team

Quick Links

  • Sitemap
  • Editorial Policy
  • Disclaimer
  • Privacy Policy

Disclaimer: Content on NameCoinNews is for informational purposes only and should not be taken as financial, legal, investment, or tax advice. The crypto market is volatile, and investors can incur losses. We are not liable if a reader incurs losses due to reliance on our content. We would strongly suggest that readers carry out their own research and consult an expert before making any investment. With the content presented on the website, we try to be as accurate as possible, but NameCoinNews does not guarantee it and is not responsible for any decisions made by the reader based on our content. Our content should not be used without our permission, which includes copying or redistribution. For more, see our Terms and Conditions and Privacy Policy.

© Copyright 2026. All Rights Reserved.