Poisoning the well: AI supply chain attacks on Hugging Face and OpenClaw
Reported 11 May 2026 by otx · Severity: medium
Threat actors are actively exploiting AI distribution platforms like Hugging Face and ClawHub to deliver malware by embedding malicious code within models, datasets, and agent extensions. Over 575 malicious skills across 13 developer accounts were identified in the OpenClaw ecosy