GoPlus: ClawHub has a vulnerability that allows for download count forgery, and popular skills may contain malicious code

By: www.chaincatcher.com|2026/03/26 11:51:10

According to a security alert released by GoPlus Security, Silverfort security researchers discovered a serious vulnerability in OpenClaw's skill repository ClawHub. Attackers can bypass all protective mechanisms by calling the internal function downloads:increment, allowing them to inflate the download count to over 20,000 in just a few minutes with a single curl request, thereby pushing malicious skills to the top of search rankings and enticing users or AI Agents to install them automatically.

Once the malicious skill is running, it can steal sensitive data such as cryptocurrency wallets and API keys. The vulnerability has been patched within 24 hours. GoPlus advises users that a high download count does not equal safety and recommends using AgentGuard for security scanning and protection.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

Projects for Modernizing Kindergartens and Purchasing Trolleybuses Completed in Ternopil

Neros Completes $250 Million Financing, Valuation Reaches $2.5 Billion

ListaDAO Addresses Third-Party Contract Vulnerability Concerns

Key Takeaways GoPlus Security revealed a vulnerability in a contract resembling those of ListaDAO. ListaDAO confirmed that their…

GoPlus: ListaDAO's liquidity staking vault was attacked, and the attacker exploited a logical vulnerability to steal funds

GoPlus Security released an analysis stating that the Liquid Staking Vault contract of ListaDAO was attacked due to a business logic flaw. The attacker triggered the share calculation function of the Dividend contract when transferring specific tokens, which affected the reward distribution logic of...

GoPlus discloses a new type of Android malware PromptSpy, which utilizes AI large models to achieve remote control of devices

GoPlus Security warns users to be cautious of a new type of Android malware called PromptSpy. This malware lures users into downloading APK files through phishing websites (such as those disguised as bank websites) and can remotely control devices after obtaining accessibility permissions.What makes...

GoPlus Releases SafuSkill, Building a Security-First AI Agent Skills Marketplace

BlockBeats News, March 12th, as the application of AI Agents in the Web3 ecosystem accelerates, Skills are gradually becoming the core capability module for Agent task execution. However, in the current market, a large number of Skills have wide-ranging permissions and lack a security audit mechanis...
...

Latest articles

More

Latest coin listings on WEEX

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com