Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITED
openclaw · clawhub

Emerging AI Supply Chain Threat in OpenClaw's Skill Marketplace

60% confidence

Description

Malicious campaigns exploiting OpenClaw's ClawHub skill marketplace through unblocked skills, including macOS infostealers, evasion techniques, and agentic threats. Attackers bypassed security measures like VirusTotal and ClawScan to deliver payloads via semantic instruction hijacking and runtime manipulation.

Affected Products

VendorProductVersions
openclawclawhub—

Related News (2 articles)

Tier D
Dark Reading3d ago
More Malicious OpenClaw Skills Threaten AI Supply Chain
→ No new info (linked only)
Tier C
Palo Alto Unit 424d ago
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
PublishedJun 23, 2026
Last enriched4d ago
Tags
aisupply chainmalwareevasionagentic threats
Trending Score27
Source articles2
Independent2
Info Completeness6/14
Missing: cve_id, versions, cvss, epss, cwe, kev, patch, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-53866EXP
OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing
Trending: 9
HIGHCVE-2026-53865EXP
OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATH
Trending: 9
HIGHCVE-2026-53853EXP
OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOS
Trending: 9
HIGHCVE-2026-53843EXP
OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device Session
Trending: 9
MEDIUMCVE-2026-53851
OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass
Trending: 8

Pin to Dashboard

Verification

State: reported
Confidence: 60%

Vulnerability Timeline

CVE Published
Jun 23, 2026
Actively Exploited
Jun 23, 2026
Exploit Available
Jun 23, 2026
Discovered by ZDM
Jun 23, 2026