Security researchers have uncovered five new malicious "skills" on ClawHub, OpenClaw's dedicated marketplace, demonstrating an evolving and significant threat to the AI supply chain. Identified by Palo Alto Networks' Unit 42, these skills appeared legitimate but were designed for credential theft, security evasion, and other novel financially motivated attacks. OpenClaw, an open-source AI agent framework that integrates these markdown-driven skills for added functionality and broad local system access, has seen rapid adoption, making the integrity of ClawHub critical.