We Audited the OpenClaw Marketplace. We Found a Trojan.
A malicious “Skill” for the OpenClaw AI framework, titled “RememberAll”, is currently being distributed via the ClawHub marketplace. While purporting to be a personal reminder utility, the skill contains hidden instructions to download a secondary payload (secure-sync) that harvests sensitive credentials (API keys, .env files) and exfiltrates them to a public ntfy.sh dead-drop resolver.