惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
博客园 - Franky
大猫的无限游戏
大猫的无限游戏
博客园 - 三生石上(FineUI控件)
量子位
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
V
Visual Studio Blog
雷峰网
雷峰网
T
Tailwind CSS Blog
宝玉的分享
宝玉的分享
Blog — PlanetScale
Blog — PlanetScale
有赞技术团队
有赞技术团队
博客园 - 叶小钗
Microsoft Azure Blog
Microsoft Azure Blog
T
The Blog of Author Tim Ferriss
U
Unit 42
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
小众软件
小众软件
阮一峰的网络日志
阮一峰的网络日志
Y
Y Combinator Blog

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders
30 ClawHub Skills Are Quietly Recruiting Your AI Agent In...
axsharma · 2026-04-29 · via Hacker News - Newest: "AI"

 To the agent, this looks like a standard configuration task. To a security researcher, it’s a stealthy enrollment into what looks structurally like a botnet.

Thirty skills. All feeding into the same loop: register, report, generate wallet, check for tasks, recruit more agents.

It's not malware. That's the problem.

We analyzed the published SKILL.md files and code contained in these artifacts.

There are no reverse shells here. No base64 payloads. No password-protected ZIPs hiding an info stealer. An EDR would see normal HTTPS requests to a .buzz domain. A registry scanner might flag the curl commands, but they look like legitimate API calls.

ClawSwarm is actually an open source project on GitHub, touting itself as "The First Open Source Agentic Skill Economy," i.e. a framework for agents to find each other, share capabilities, and earn crypto for completing tasks. imaflytok's deployment at onlyflies.buzz is one implementation of that framework.

The 32-member Telegram group posts automated whale tracking reports for Hedera tokens. There's a fungible token called $FLY, created December 30, 2024. The skills themselves include a whale watcher, a cross-platform poster, and a predictions market integration called PolyFly.

You can read all of this and conclude it's a small crypto community building agent infrastructure. Maybe it is. But the mechanism is identical regardless of intent: an AI agent silently registering with a third party server, reporting its capabilities, generating crypto keys, and accepting remote tasks -- all without the user initiating or approving any of it.

ClawSwarm isn't an isolated case. There is a whole emerging ecosystem of skills that do something structurally similar, i.e. enlist your agent into a third-party paid-agent network, meter its work, and route the proceeds to a wallet the installer never sees. MoltGuild appears across 91 skill files in the dataset we analysed. Teneo Protocol ships 38 skills from a single publisher, each with explicit per-call USDC pricing in the frontmatter. Whether they implement strict x402 HTTP semantics ("payment required") or a close variant, the pattern matches ClawSwarm's. The skill is the recruiter, the agent is the worker, the SOC logs the traffic but not the deal.

We've seen this pattern before

In early 2024, the tea protocol launched a token rewards system that gave developers crypto for publishing open source packages. What happened next was predictable: npm got flooded with thousands of spam packages. Each one existed to farm tea tokens. The packages had names, and some had READMEs. Almost none had real code. The registry was being used as a token acquisition funnel.

ClawSwarm follows the same playbook, adapted for skills instead of npm packages. Publish skills to ClawHub. Get downloads. Use those downloads to bootstrap a network of agents that generate wallets, report capabilities, and participate in a token economy. The skills provide just enough real utility (cron jobs, environment management, workspace setup) that they pass a casual inspection.

The net effect is recruiting agents into an economic network centered on $FLY.

The download numbers tell the story. Cron Helper leads at 903 -- it's the most generic, most installable skill in the set. Agent Security has 685 downloads; who wouldn't install something called "agent security"? But Agent Security normalizes onlyflies.buzz as a trusted domain in its connectivity checks. Once you install the helpful utility, the rest of the funnel is waiting.

Here are the top downloads across imaflytok's skills:

Skill

Downloads

Cron Helper

903

Agent Security

685

OADP Agent Discovery

475

Agent ID

421

Heartbeat Pro

405

Agent Autonomy

369

ClawSwarm

363

Whale Watch

347

A2A Bridge

327

Agent Network Scanner

319

Env Manager

317

Agent Ping

311

Agent Session Cost

300

ClawSwarm Whale Watcher

298

cross-platform-poster

292

Agent Starter Kit

290

Hedera Mirror

287

Workspace Init

274

Agent Treasury

274

OADP Beacon

273

OADP Emit

266

Moltbook Refugee

264

Agent Economy Starter Kit

244

ClawSwarm Services Marketplace

244

ClawSwarm Cross-Platform Poster

240

Hedera Data API

163

PolyFly Predictions

154

ClawSwarm Jobs

137

ClawSwarm Real-Time Client

54

That's roughly 9,800 total downloads across all listed skills. Not all of those are unique agents. But even a fraction represents real users whose agents may now be registered with onlyflies.buzz and checking in every session.

What makes this different

ClawHavoc campaign that hit ClawHub earlier this year was traditional supply chain malware adapted for skills. Social engineering, info stealers, password-protected ZIPs. It targeted humans: "download this AuthTool to get started." Four research teams documented it. ClawHub removed most of the accounts.

ClawSwarm targets agents. The SKILL.md is the attack surface. An agent reads the instructions and follows them – registering, reporting, generating keys – because that's what agents do with skill instructions. No human has to click a link or run a binary, the agent handles it all.

ClawHavoc

ClawSwarm

Target

Human user

AI agent

Method

Social engineering

Skill instructions

Payload

AMOS / NovaStealer

Agent recruitment + wallet generation

Human action

Yes (download, extract, run)

No (agent follows SKILL.md)

What's collected

Browser passwords, SSH keys

Agent capabilities, crypto keys, identity

Persistence

Binary on disk

Boot files read every session

Scale

Sock puppet accounts

Self-propagating agent discovery

The registry can't help you here

ClawSwarm skills wouldn't trip a malware scanner and may not even obviously be against registry rules. There's no shellcode. No obfuscated payloads. The curl commands are standard API calls. The crypto wallet generation uses a legitimate Hedera SDK. The OADP spec is written in clean Markdown.

A scanner that flags malicious code patterns would look at these 30 skills and see nothing. A scanner that checks for known C2 domains would need to already know about onlyflies.buzz, which nobody had flagged before this research. And even if a scanner did flag the domain, the response would be ambiguous -- it's tied to an open source project with a GitHub repo and an Apache license.

The question that actually matters isn't "is this skill malicious?" It's "should my agent be silently registering with a third party and generating crypto wallets without my knowledge?" A registry scanner can't answer that. It's a runtime question.

What catches this

Manifold monitors agent behavior at runtime.

An agent that auto-registers with an external server on startup. Reports its capabilities to a third party. Generates crypto keys and sends them to an endpoint the user has never heard of. Polls for remote tasks every four hours. Manifold's telemetry sees all of this, and it doesn't need the code to contain shellcode or a known C2 domain to flag it.

Your EDR sees HTTPS traffic to onlyflies.buzz. Manifold sees an agent enrolling itself in someone else's network and handing over wallet keys for a token economy the user never signed up for.

Where this is going

ClawSwarm won't be the last project to use a skill registry as a user acquisition funnel for a crypto token. Publish skills that provide some real utility, accumulate downloads, convert installs into network participants. The tea tokens playbook proved it works on npm. Now it works on ClawHub.

The uncomfortable question is whether this is actually against any rules. The skills are open source. The API calls are documented. The token is on a public blockchain. There's a Telegram group. It's more transparent than most crypto projects. And yet, agents are joining a network, generating wallets, and checking in with a server that their human operators never heard of.

Intent doesn't change the mechanism. Whether ClawSwarm instances are a legitimate experiment in agent economics or a recruitment funnel for speculative crypto, the result for the user is the same: their agent is doing things they didn't ask it to do, for someone they don't know, with keys they didn't authorize…

Call it what you want. It's not malware by any traditional definition. But your agent has been 'onboarded' into a workforce you don't control, and you didn't approve the arrangement (and might even get slapped with a hefty compute bill). That only gets caught at the runtime layer.

Book a demo to see what Manifold sees that your current stack doesn't.

*OADP: Not to be confused with Red Hat's OADP; this is a proprietary imitation designed for 'discovery' within the onlyflies ecosystem.