GachiLoader adopts AI skill lure

Reported 29 Apr 2026 by otx · Severity: medium

Threat actors are exploiting AI agent skill formats as a novel attack vector, using convincingly packaged OpenClaw skills to distribute malicious payloads. The latest campaign employs pure social engineering, with skills containing no malicious code themselves but instead trickin