AI Briefing
KO

Malicious Code Discovered in OpenClaw Skills Repository

·2026.04.25 16:30

Key point

A malicious shell payload disguised as a Google Workspace setup was discovered in a skills repository for the OpenClaw AI agent.

Details

Malicious code was found embedded in the gog (Google Workspace CLI integration) skill within github.com/openclaw/skills, a skills repository for the OpenClaw AI agent.

The skill's SKILL.md file contained a base64-encoded bash command disguised as a macOS setup process. When decoded, it reveals a curl-pipe-to-bash style payload that fetches and executes a script from a specific IP (91.92.242.30).

Key Indicators of Compromise (IoC):

  • Target path: skills/zaycv/googleworkspace/SKILL.md
  • Payload domain: app-distribution.net
  • C2 IP: 91.92.242.30
  • Disguise keywords: OpenClawDriver, OpenClawWinDriver

Users should check their local environment for infection by searching for keywords such as app-distribution, 91.92.242, and OpenClawDriver. Caution is needed regarding whether this repository is the official one or an attack via typosquatting.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.