Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
openclaw-security-monitor — Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks. | Kitploit
Tools/GitHubGitHub/adibirzu/openclaw-security-monitor
Defensive ToolsVulnerability ScannersForensicsWeb SecurityNetwork SecurityMalware AnalysisThreat IntelligenceSupply Chain SecurityIntrusion Detection

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Learning & Education
Incident Response
Log Analysis
GitHubadibirzu/openclaw-security-monitor

openclaw-security-monitor

Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.

View Repository
48512012 days agoReviewed by Kitploit
Share

OpenClaw Security Monitor

Proactive security monitoring, threat scanning, and real-time visibility for OpenClaw deployments. Detects threats from the ClawHavoc campaign (824+ malicious skills), AMOS stealer, Vidar infostealer, GhostSocks proxy malware, ClawJacked WebSocket brute-force, workspace plugin auto-loading attacks, shared-auth scope escalation, approval replay/integrity bypasses, supply chain attacks, memory poisoning, log poisoning, browser relay hijacking, TAR traversal, SSRF, SHA-1 cache poisoning, MCP tool poisoning, SANDWORM worm propagation, 170 advisories, and 500+ CVEs.

Why This Exists

In late January 2026, security researchers found that 12% of all ClawHub skills were malicious — 341 out of 2,857 skills across multiple campaigns. By mid-February, this expanded to 824+ malicious skills with 1,184 malicious packages across 12 publisher accounts (Antiy CERT). The Snyk ToxicSkills study found 36% of all ClawHub skills contain security flaws (3,984 scanned).

The primary campaign, ClawHavoc, delivered the Atomic Stealer (AMOS) macOS infostealer targeting crypto wallets, SSH credentials, and browser passwords. In February, Hudson Rock discovered Vidar infostealer variants specifically targeting OpenClaw agent identities — stealing openclaw.json, device.json, soul.md, and memory.md files.

Meanwhile, CVE-2026-25253 demonstrated that a single malicious link could achieve full remote code execution on any OpenClaw instance through WebSocket hijacking — even those bound to localhost. The ClawJacked attack (Feb 26, Oasis Security) showed that malicious websites can brute-force localhost WebSocket passwords with no rate limiting. CVE-2026-28363 (CVSS 9.9) revealed a critical safeBins bypass via GNU long-option abbreviations. In total, 170 advisories and 500+ CVEs have been tracked across project and third-party disclosures including SSRF, exec bypass, ACP auto-approval bypass, webhook forgery, log poisoning, and more. The March 19-21 batch (CVE-2026-32013, CVE-2026-32014, CVE-2026-32025, CVE-2026-32042, CVE-2026-32048, CVE-2026-32051, CVE-2026-32055, CVE-2026-32056, CVE-2026-32064) added symlink traversal, sandbox escape, shell environment RCE, unauthenticated VNC observer access, and device identity/metadata spoofing. The April 16 wave added Matrix room-control sender-auth bypass (GHSA-2gvc-4f3c-2855), webchat media local-root bypass (GHSA-mr34-9552-qr95), gateway SecretRef stale bearer auth (GHSA-xmxx-7p24-h892), and config.get redaction bypass (GHSA-8372-7vhw-cm6q). The April 21-25 rollups added setup-api.js cwd execution (GHSA-r39h-4c2p-3jxp), webhook SecretRef route-secret replay (GHSA-q8ff-7ffm-m3r9), gateway config mutation guard bypass (GHSA-cwj3-vqpp-pmxr), dotenv connector/runtime overrides, MCP owner-context/tool-policy issues, OpenShell FS bridge escapes, and additional SSRF/media hardening. The June 2026 rollup added MCP Streamable HTTP redirect header leakage (CVE-2026-53840), workspace dotenv/env command influence (CVE-2026-53842, CVE-2026-53846, CVE-2026-53858, CVE-2026-53864), exec allowlist bypasses (CVE-2026-53853, CVE-2026-53855, CVE-2026-53861, CVE-2026-53866), service PATH hijacking (CVE-2026-53865), and revoked device-token/scope abuse (CVE-2026-53843, CVE-2026-53847, CVE-2026-53852). Unit 42 also documented five evasive ClawHub skills from February-May 2026, including TradingView paste-site lures, an oversized padded README dropper (omnicogg), runtime affiliate injection (money-radar), and agentic front-running (letssendit).

135,000+ instances are exposed across 82 countries, with 12,812 exploitable via RCE. Major security firms including CrowdStrike, Bitdefender, Palo Alto Networks, Cisco, and Kaspersky have issued advisories. Meta has banned OpenClaw from corporate devices.

This project provides defense-in-depth monitoring for self-hosted OpenClaw installations. Minimum safe version: v2026.5.26.

Features

  • 41-point security scan covering C2 infrastructure, stealers, reverse shells, credential exfiltration, memory poisoning, SKILL.md injection, WebSocket hijacking, ClawJacked brute-force, SSRF, safeBins bypass, ACP auto-approval, PATH hijacking, env override injection, deep link truncation, log poisoning, SHA-1 cache poisoning, Google Chat webhook bypass, CSWSH, MCP tool poisoning, SANDWORM worm detection, rules file backdoor, setup-api.js plugin hijacks, workspace plugin auto-loading, shared-auth scope abuse, exec approval replay, file-padding evasion, malicious skill-name patterns, DM/tool/sandbox policies, persistence mechanisms, plugin auditing, Docker security, and more
  • IOC database with known C2 IPs, malicious domains, file hashes, publisher blacklists, and skill name patterns
  • Auto-updating IOC feeds that pull latest threat intelligence from upstream
  • Bundle-plugin manifest for clawhub package publish --family bundle-plugin
  • Web dashboard (dark-themed, zero dependencies) with real-time status, process trees, network monitoring, and scan history
  • Daily automated scans with Telegram alerting
  • Process ancestry tracking via witr integration

Quick Start

# Clone into OpenClaw skills directory
git clone https://github.com/adibirzu/openclaw-security-monitor.git \
  ~/.openclaw/workspace/skills/openclaw-security-monitor

cd ~/.openclaw/workspace/skills/openclaw-security-monitor

# Make scripts executable
chmod +x scripts/*.sh scripts/remediate/*.sh

# Run a 41-point scan (read-only, no system changes)
./scripts/scan.sh

# Preview what remediation would do (dry-run, no changes)
./scripts/remediate.sh --dry-run

# Start the web dashboard (read-only, localhost:18800)
node dashboard/server.js

# Scan all installed ClawHub skills
./scripts/clawhub-scan.sh

# Update IOC database (interactive, asks for confirmation)
./scripts/update-ioc.sh

Bundle Plugin

This project is also publishable as a ClawHub bundle plugin.

# Install the bundle plugin variant
openclaw plugins install clawhub:openclaw-security-monitor-bundle

Optional persistence (manual, not auto-installed):

# Install daily cron (06:00 UTC) — requires explicit user action
crontab -l | { cat; echo "0 6 * * * $(pwd)/scripts/daily-scan-cron.sh"; } | crontab -

Architecture

openclaw-security-monitor/
  .codex-plugin/
    plugin.json          # Bundle-plugin manifest for ClawHub/OpenClaw plugin publishing
  scripts/
    scan.sh              # 41-point threat scanner (v5.5.0)
    remediate.sh         # Orchestrator: scan + per-check remediation
    remediate/
      _common.sh         # Shared helpers (log, confirm, fix_perms)
      check-01-c2-ips.sh ... check-41-device-identity-spoofing.sh  # 41 consolidated per-check scripts
      check-42-*.sh ... check-62-*.sh  # retained legacy advisory-specific helpers
    clawhub-scan.sh      # Scan all installed ClawHub skills against IOC database
    dashboard.sh         # CLI security dashboard with witr
    network-check.sh     # Network activity monitor
    daily-scan-cron.sh   # Cron wrapper + Telegram alerts
    telegram-setup.sh    # Telegram notification setup
    update-ioc.sh        # IOC database updater
  ioc/
    c2-ips.txt           # Known C2 IP addresses
    malicious-domains.txt # Payload/exfil domains
    file-hashes.txt      # Known malicious file hashes
    malicious-publishers.txt  # Blacklisted ClawHub accounts
    malicious-skill-patterns.txt  # Malicious skill naming patterns
  dashboard/
    server.js            # Node.js HTTP server (zero npm deps)
    index.html           # Single-file dark-themed SPA
  docs/
    threat-model.md      # Threat model and attack vectors

Scan Checks (41)

Download Tool