AI-Assisted Software DevelopmentFeb 1, 2026
'ClawHavoc': 900+ malicious agent 'skills' pushed through a third-party marketplace
A campaign dubbed ClawHavoc pushed first 341, then more than 900 malicious agent 'skills' through a third-party marketplace in early 2026. Some of them rewrote the agent's memory file so the compromise survived deleting the skill. It is the agent-era version of a supply-chain attack: the extension you installed can carry an instruction the model will obey.
What it means Any skill, tool, or config you didn't write deserves the same scrutiny as a code dependency — and 'delete the skill' is not the same as 'undo what it did.'
Where it came from Koi Security