{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/virustotal-malicious-openclaw-skills-2026/",
 "asOf": "2026-09-26",
 "id": "virustotal-malicious-openclaw-skills-2026",
 "date": "2026-02-02",
 "datePrecision": "day",
 "title": "VirusTotal finds hundreds of malicious OpenClaw agent skills distributing stealers and backdoors",
 "lane": "attack",
 "kind": "malware",
 "summary": "VirusTotal analyzed more than 3,016 OpenClaw skill packages and reports hundreds with malicious behavior, including data exfiltration, backdoors, malware droppers such as Atomic Stealer, and persistent instruction files that manipulate the agent. One publisher accounted for 314 malicious skills; VirusTotal added native scanning of skill packages.",
 "whyItMatters": "Agent skill marketplaces became an in-the-wild malware distribution channel within months of launch.",
 "actors": [
  "virustotal",
  "openclaw"
 ],
 "topics": [
  "agent-supply-chain",
  "ai-malware"
 ],
 "atlas": [
  "supply-chain",
  "memory",
  "tools"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://blog.virustotal.com/2026/02/",
   "publisher": "VirusTotal",
   "title": "From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized (and Part II, 2026-02-05)",
   "date": "2026-02-02",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "More than 3,016 OpenClaw skills analyzed; 314 malicious skills from a single publisher.",
   "locator": "VirusTotal February 2026 posts"
  },
  {
   "fact": "Atomic Stealer (AMOS) found among macOS payloads.",
   "locator": "VirusTotal February 2026 posts"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [
  "agent-data-exfiltration",
  "malicious-agent-extensions",
  "memory-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}