Skip to content

ClawHavoc Supply Chain Attack

341+ Malicious Skills on ClawHub

Security researchers discovered that threat actors uploaded 341+ malicious skills to ClawHub, the official skill repository. These appeared legitimate but contained hidden malware and backdoors.

ASF Protection

  • Skill signing with cryptographic verification
  • YARA rules detect known malware patterns
  • Sandbox testing before deployment
  • Trust scoring for skill publishers
  • Auto-update disable option

Learn more about ASF