VirusTotal analyzed more than 3,016 OpenClaw skill packages and reports hundreds with malicious behavior, including data exfiltration, backdoors, malware droppers such as Atomic Stealer, and persistent instruction files that manipulate the agent. One publisher accounted for 314 malicious skills; VirusTotal added native scanning of skill packages.
Why it matters
Agent skill marketplaces became an in-the-wild malware distribution channel within months of launch.
Key facts
As stated in the sources, with where to find them.
- More than 3,016 OpenClaw skills analyzed; 314 malicious skills from a single publisher.VirusTotal February 2026 posts
- Atomic Stealer (AMOS) found among macOS payloads.VirusTotal February 2026 posts
Findings that cite this record
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
Related records
Aug 26, 2025
Apr 15, 2026
Sep 25, 2025
Aug 5, 2025
Jul 23, 2025
Jul 9, 2025