Security researchers discovered widespread malware distribution through OpenClaw's skill marketplace, with VirusTotal identifying hundreds of malicious skills among 3,016 analyzed. Attackers exploited the platform's markdown-based skill format to deliver info-stealers through social engineering, instructing users to execute base64-encoded commands or download malicious payloads. One campaign traced 314 malicious skills to a single publisher. OpenClaw responded by integrating VirusTotal scanning into ClawHub, though researchers warn this won't catch all threats. The incident highlights a new supply chain attack vector where AI agent skills blur the line between documentation and execution, making traditional security tools ineffective against natural language-based malware delivery.