GoPlus: ClawHub has a fake download count vulnerability, and popular skills may contain malicious code

robot
Abstract generation in progress

Deep Tide TechFlow News, March 26 — According to a security alert released by GoPlus Security, Silverfort security researchers discovered a serious vulnerability in OpenClaw’s skill repository ClawHub. Attackers can bypass all protection mechanisms by calling the internal function downloads:increment, and with just one curl request, they can increase download counts to over 20,000 within minutes. This can push malicious skills to the top of search rankings, tricking users or AI Agents into automatically installing them.

Once malicious skills are run, they can steal sensitive data such as crypto wallets and API keys. The vulnerability has been patched within 24 hours. GoPlus warns users that high download numbers do not equate to safety, and recommends using AgentGuard for security scanning and protection.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin