{"id":11237,"date":"2026-02-03T10:58:50","date_gmt":"2026-02-03T03:58:50","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11237"},"modified":"2026-06-25T09:53:07","modified_gmt":"2026-06-25T02:53:07","slug":"warning-ai-assistant-utility-is-being-used-to-spread-malicious-code-please-abort-the-convenience-of-setting","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2026\/02\/03\/warning-ai-assistant-utility-is-being-used-to-spread-malicious-code-please-abort-the-convenience-of-setting\/","title":{"rendered":"Warning: AI assistant utility is being used to spread malicious code, please abort the convenience of setting"},"content":{"rendered":"<div style=\"text-align: justify\"><b>A new wave of attacks is targeting OpenClaw users \u2013 open &#8211; source personal AI assistants being installed by many to run on their own computers. Instead of a front &#8211; loading attack, hackers opted for a more sophisticated way: blending the code into the &#8220;skills&#8221; &#8211; extensions that allowed OpenClaw to do more.<\/b><br \/>\n\u200b<\/div>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper js-lbImage\" title=\"1770086108408.png\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\" data-single-image=\"1\" data-src=\"https:\/\/whitehat.vn\/attachments\/1770086108408-png.18393\/\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1770086108408.png\" src=\"https:\/\/whitehat.vn\/attachments\/1770086108408-png.18393\/\" alt=\"1770086108408.png\" width=\"845\" height=\"442\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<p>\u200b<\/p>\n<\/div>\n<div style=\"text-align: justify\">\n<p>According to cybersecurity studies, of the more than 2,800 skills posted on the ClawHub repository, at least 300 contained malicious code. What&#8217;s remarkable is that they&#8217;re not &#8220;weedy.&#8221; These utilities are disguised as familiar sounding tools: crypto price tracking bots, crypto trading bots, YouTube briefers, financial utilities, even &#8220;auto update&#8221; bots. The name and documentation are all well-written, leading users to believe it&#8217;s a real tool.<\/p>\n<p>The &#8220;Trap&#8221; should be in the installation instructions. The user is required to download an additional subfile, or copy a command line to run in the computer. On the surface, that seems like a normal engineering step. But in fact, it&#8217;s this act that opens the door to malicious code. Once activated, the malware silently collects all kinds of sensitive information: browser passwords, crypto wallet keys, exchange API keys, SSH accounts, stored data, etc. In other words, if your computer has something &#8220;worth the trouble,&#8221; malware will try to take it away.<br \/>\n\u200b<\/p>\n<\/div>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper js-lbImage\" title=\"1770086204286.png\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\" data-single-image=\"1\" data-src=\"https:\/\/whitehat.vn\/attachments\/1770086204286-png.18394\/\"><img decoding=\"async\" class=\"bbImage\" title=\"1770086204286.png\" src=\"https:\/\/whitehat.vn\/attachments\/1770086204286-png.18394\/\" alt=\"1770086204286.png\" width=\"686\" height=\"587\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<p><i><br \/>\nMalicious utilities (skills) associated with the same release account \u2013 Image: OpenSourceMalware<\/i>\u200b<\/p>\n<\/div>\n<div style=\"text-align: justify\">\n<p>The risk is even greater because OpenClaw is an AI assistant with deep access to the system: reading files, connecting emails, calling APIs, interacting with the Internet, and saving long &#8211; term &#8220;memories&#8221;. When a malicious utility is installed, the attacker can not only steal user data but can also use the AI assistant itself as an &#8220;inside man&#8221; to serve malicious purposes later.<\/p>\n<p>The underlying reason for this is the open-source ClawHub repository: virtually anyone can upload their skills, and censorship is limited. While the developer added features for users reporting suspicious skills, this was mostly &#8220;firefighting&#8221;, making it difficult to keep up with the pace of mass launch of malicious add &#8211; ons.<\/p>\n<p>For Vietnamese users, anyone with a &#8220;treat it convenient&#8221; habit could become a victim. Some simple but effective principles: do not install unfamiliar plugins just because the name sounds good; be absolutely wary of instructions that require running commands, adding external files; limit AI assistants to too wide access to the machine; if possible, run OpenClaw in a remote environment (virtual machine, container).<br \/>\n\u200b<\/p>\n<\/div>\n<div style=\"text-align: right\"><b><i>According to The Hacker News, Bleeping Computer<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/canh-bao-tien-ich-cho-tro-ly-ai-bi-loi-dung-de-phat-tan-ma-doc-hay-bo-thoi-quen-thay-tien-la-cai.19193\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/canh-bao-tien-ich-cho-tro-ly-ai-bi-loi-dung-de-phat-tan-ma-doc-hay-bo-thoi-quen-thay-tien-la-cai.19193\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new wave of attacks is targeting OpenClaw users \u2013 open &#8211; source personal AI assistants being installed by many to run on their own computers. Instead of a front &#8211; loading attack, hackers opted for a more sophisticated way: blending the code into the &#8220;skills&#8221; &#8211; extensions that allowed OpenClaw to do more. \u200b [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11237","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11237","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11237"}],"version-history":[{"count":2,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11237\/revisions"}],"predecessor-version":[{"id":11624,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11237\/revisions\/11624"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}