Poisoning the well: AI supply chain attacks on Hugging Face and OpenClaw

Reported 11 May 2026 by otx · Severity: medium

Threat actors are actively exploiting AI distribution platforms like Hugging Face and ClawHub to deliver malware by embedding malicious code within models, datasets, and agent extensions. Over 575 malicious skills across 13 developer accounts were identified in the OpenClaw ecosy