TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

The Register Security

30 ClawHub skills secretly turn AI agents into a crypto swarm

Jessica Lyons · 2026-04-29 · Read original ↗

ATT&CK techniques detected

2 predictions
T1195.001Compromise Software Dependencies and Development Tools
57%
"' t approve any of this activity and doesn ’ t see it happening. in addition to being the name of the crypto - swarm campaign sharma documented, clawswarm is also an open source agentic skill framework on github. the imaflytok ' s skills open at onlyflies. buzz are one such imple…"
T1195.001Compromise Software Dependencies and Development Tools
51%
"##mmy packages flooded the npm registry to farm tea points. clawswarm, according to sharma, " follows the same playbook, " but uses skills instead of npm packages. " whether clawswarm instances are a legitimate experiment in agent economics or a recruitment funnel for speculative…"

Summary

Yet another reason not to feast on OpenClaw

Thirty ClawHub skills published by a single author are silently co-opting AI agents and creating a mass cryptocurrency mining swarm – without any malware or user consent.…