OpenClaw Faces Supply-Chain Plugin Poisoning Attacks
On Feb. 9, 2026 security firms SlowMist and Koi Security reported that OpenClaw's ClawHub marketplace hosted hundreds of malicious plugins. The compromised extensions deploy infostealers such as Atomic Stealer and target local AI agents that automate workflows, interact with services, and control devices. Organizations and developers are urged to audit plugin sources, verify signatures, and isolate agent runtimes to limit exposure.
Key Points
- 1Finds hundreds of ClawHub plugins compromised, distributing infostealers including Atomic Stealer to agent hosts
- 2Signals elevated supply-chain poisoning risk for agent marketplaces, enabling credential theft and broader system compromise
- 3Advises developers and operators to audit plugins, verify digital signatures, and sandbox or isolate agent runtimes
Scoring Rationale
Verified security firm reports raise concern across agent ecosystems, but coverage is platform-specific and lacks deep forensic detail
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


