Observed Signal · Feb 9, 2026 · Partnership · Source: Trending Topics · Impact: 3/5 · Sentiment: Positive

OpenClaw Partners with VirusTotal to Fight AI Agent Malware

Executive Signal Summary

OpenClaw, the open-source AI assistant developed by Austrian developer Peter Steinberger, has partnered with Google-owned VirusTotal to protect its ClawHub skill marketplace from malicious extensions. The multi-stage security system hashes uploaded skills with SHA-256, checks them against VirusTotal's database, and uses the Code Insight AI function powered by Gemini to analyze actual code behavior. Security researchers had found hundreds of malware-infected extensions capable of stealing passwords, executing unauthorized commands, and downloading external malware. While the signature-based approach catches known trojans, carefully crafted prompt injections can still bypass detection. All active extensions undergo daily rescans. OpenClaw has also appointed Jamieson O'Reilly — founder of Dvuln and co-founder of Aether AI — as lead security advisor, and plans to publish a threat model, security roadmap, and vulnerability disclosure process.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

AI agent marketplaces are emerging as critical infrastructure for autonomous software distribution; OpenClaw's malware problem highlights systemic security risks in agentic AI, and the VirusTotal partnership establishes a security baseline relevant to the broader AI agent ecosystem.

SIGNAL RADAR

Track OpenClaw Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • OpenClaw entered a partnership with VirusTotal to scan ClawHub skill uploads for malware using SHA-256 hashes and the VirusTotal API.
  • Security researchers found hundreds of malware-infected extensions on ClawHub that could steal passwords and exfiltrate sensitive data.
  • VirusTotal's Code Insight function, powered by a Large Language Model and Gemini, analyzes uploaded extension code for malicious behavior.
  • All active ClawHub extensions undergo daily rescans to detect subsequently injected malware.
  • OpenClaw appointed Jamieson O'Reilly, founder of Dvuln and co-founder of Aether AI, as lead security advisor.

Connected Companies & Entities

3 Entities mapped

“The developer of the AI assistant OpenClaw has now entered into a partnership with VirusTotal to protect the skill marketplace ClawHub from ...”

“Google's threat database now scans all uploaded skills for malware components and suspicious code....”

“It has seen great hype, but was already called a security nightmare: the open-source AI assistant OpenClaw (formerly Clawdbot/Moltbot) by Au...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: Trending Topics•Published: Feb 9, 2026
Original Coverage Title: ““Security Nightmare”: How OpenClaw Is Fighting Malware in Its AI Agent Marketplace”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

AI & AgentsOct 8, 2026

Google launches unified agentic AI for Gemini

At a Google Cloud event on Thursday, Google announced it is bringing agentic AI to its Gemini assistant, launching a unified agent that can autonomously plan and execute tasks on behalf of users. Aimed initially at businesses, the agent can connect to internal systems and external tools, use custom skills, and even choose from third-party models like Anthropic's Claude. It will have its own Workspace account with an email address, and will write its own audit trail. Early testers include On, Shopify, and PayPal. Gemini has over 1 billion monthly active users, and nearly 90% of Fortune 100 companies use Gemini Enterprise.

Read assessment
Policy UpdateOct 8, 2026

US Government Excludes Microsoft from Visa Program

The US government has barred Microsoft from participating in the permanent residency process for foreign workers with H-1B visas, accusing the company of abusing the program. Vice President JD Vance stated that Microsoft laid off 6,000 American employees last year while benefiting from 6,300 H-1B visa holders. The Department of Labor, led by Keith Sonderling, will not accept new permanent residency applications from Microsoft, as well as several consulting firms and Adobe. This action comes weeks before the midterm elections and reflects the Trump administration's broader criticism of the H-1B program, which it claims disadvantages American workers. Microsoft has not yet responded. The move could impact the tech industry's ability to retain skilled foreign talent.

Read assessment
RegulationOct 8, 2026

US suspends Microsoft, Adobe from green card labor program

The Trump administration has suspended Microsoft, Adobe, and six other major tech firms—Capgemini, Cognizant, HCL, Infosys, Tata, and Wipro—from the U.S. Permanent Labor Certification program, which facilitates green cards for skilled foreign workers. Secretary of Labor Keith Sonderling cited active federal investigations and alleged fraud, noting that no new or pending applications from these companies will be accepted. Vice President JD Vance accused Microsoft of replacing laid-off workers with H-1B visa holders. Microsoft defended its practices, stating that most U.S. employees are American and that 80% of its H-1B petitions were for existing employees. The announcement was made during a White House summit on H-1B fraud, and the administration also plans to investigate nine universities, including Harvard, Yale, and Stanford, over student visa program abuse.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.