OpenClaw Plugin Hub Hit by Massive Supply Chain Poisoning Attack
OpenClaw's plugin ecosystem suffered a significant security breach as hackers infiltrated its ClawHub with hundreds of malicious skills. These compromised plugins, disguised as legitimate dependency installers, exploited weak review processes to distribute backdoors. SlowMist's analysis revealed a coordinated attack targeting crypto and finance users through AI-powered extensions.
The attackers Leveraged OpenClaw's trusted platform status to silently exfiltrate data, using encoded payloads to steal files and credentials. A single domain and previously flagged IP address connected most infected plugins, suggesting a sophisticated, focused operation. This incident highlights growing vulnerabilities in AI plugin ecosystems, particularly those serving financial markets.
Security researchers warn that such supply chain attacks pose systemic risks to decentralized finance platforms. The breach underscores the urgent need for stronger vetting mechanisms as malicious actors increasingly target crypto-native tools through trusted distribution channels.