Skip to content

Add scan check: detect ClawHavoc IOC patterns #62

@kw2828

Description

@kw2828

Scan installed skills for known ClawHavoc indicators of compromise - suspicious install scripts in SKILL.md, known malicious publisher names, C2 domain patterns, and obfuscated shell commands.

Reference: Antiy CERT ClawHavoc analysis (1,184 malicious packages across 12 publisher accounts).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No fields configured for Feature.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions