Skip to main content

Malwar

12% of ClawHub skills are malicious. A Snyk security audit found 341 trojanized skills delivering the AMOS infostealer to 300,000 users — and that was just the first wave. By February, 824+ malicious skills were live across 10,700+ listings. VirusTotal missed all of them. Code scanners missed all of them. Malwar catches them.

pip install malwar
malwar db init
malwar scan SKILL.md

PyPI version License CI Python Docker Docs


Why This Exists

I was installing Claude Code skills from ClawHub without a second thought — until the ClawHavoc campaign dropped. Hundreds of skills were trojanized with the AMOS infostealer, targeting wallet keys, SSH credentials, and agent memory files. The attacks weren't binaries or exploit code. They were natural language instructions hidden in Markdown, telling the AI to run curl | bash as a "prerequisite." No existing security tool is built to catch that. So I built one.

How It Works

SKILL.md → Rule Engine → URL Crawler → LLM Analyzer → Threat Intel → Verdict
             <50ms         1-5s          2-10s           <100ms
Layer What it catches
Rule Engine Obfuscated commands, prompt injection, credential exposure, exfiltration, agentic financial fraud, scanner evasion (30 rules)
URL Crawler Malicious URLs, domain reputation, redirect chains to C2 infrastructure
LLM Analyzer Social engineering, hidden intent, context-dependent attacks invisible to regex
Threat Intel Known IOCs, campaign attribution, threat actor fingerprints

Full pipeline details: Architecture

Quick Start

malwar scan SKILL.md                    # scan a file
malwar scan skills/                     # scan a directory
malwar scan SKILL.md --format sarif     # CI/CD output
malwar scan SKILL.md --no-llm          # skip LLM (fast + free)
malwar crawl scan beszel-check          # scan a ClawHub skill by slug
malwar crawl url https://example.com/SKILL.md  # scan any remote SKILL.md
malwar crawl monitor                    # scan the whole registry, diff vs. yesterday
$ malwar scan suspicious-skill.md

  MALICIOUS  Risk: 95/100  Findings: 4

  MALWAR-OBF-001   Base64-encoded command execution        critical   L14
  MALWAR-CMD-001   Remote script piped to shell            critical   L22
  MALWAR-EXFIL-001 Agent memory/identity file access       critical   L31
  MALWAR-MAL-001   ClawHavoc campaign indicator            critical   L14

  Scan completed in 42ms (rule_engine, threat_intel)

For development:

git clone https://github.com/Ap6pack/malwar.git && cd malwar
pip install -e ".[dev]"
malwar db init

Full command reference: CLI Guide

API

malwar serve    # http://localhost:8000
curl -X POST http://localhost:8000/api/v1/scan \
  -H "Content-Type: application/json" \
  -d '{"content": "...", "file_name": "SKILL.md"}'

30+ endpoints covering scan submission, results, SARIF export, signatures CRUD, campaigns, reports, dashboard analytics, audit logs, and RBAC. Auth via X-API-Key header.

Full endpoint reference: API Docs

Web Dashboard

Built-in browser UI at http://localhost:8000 when running the API server.

Dashboard

Scan Detail Campaigns
Signatures Scan History

React 19 · TypeScript · Vite · Tailwind CSS 4 · Recharts

Continuous Monitoring

Catching one malicious skill is good; catching the next campaign while it's still spreading is the point. malwar crawl monitor scans every skill in the registry, saves a snapshot, and diffs it against the previous run:

malwar crawl monitor                    # full sweep → snapshot → diff
malwar crawl monitor --fail-on-malicious   # non-zero exit when skills newly turn malicious

It surfaces exactly what changed since yesterday — newly published, removed, trojanized updates (content changed under the same version), and verdict regressions (a skill that was clean is now flagged). The sweep is cheap: rule engine + threat intel on everything, LLM escalation only on hits. Snapshots live in data/registry-snapshots/, so committing them turns git diff into a permanent, auditable record of the registry's daily threat surface. Run it on a schedule (cron, CI, or a Claude Code trigger) for ongoing, hands-off security research.

Docker

docker compose up -d    # API + Dashboard at http://localhost:8000

Multi-stage build: Node.js compiles the frontend, Python 3.13-slim runs the backend.

Full deployment guide: Deployment

Configuration

All settings via environment variables with MALWAR_ prefix or .env file. Key settings:

Variable Default Description
MALWAR_API_KEYS (empty) API keys (empty = auth disabled)
MALWAR_ANTHROPIC_API_KEY (empty) Anthropic key for LLM layer (falls back to ANTHROPIC_API_KEY or an ant auth login / Claude Code CLI login)
MALWAR_DB_PATH malwar.db SQLite database path

All 40+ configuration options →

Development

pytest                                # 1,596 tests
ruff check src/ tests/                # lint
mypy src/                             # type check

51 test fixtures: 6 benign, 23 malicious (synthetic), 3 real-world benign, 6 real-world malicious, 13 real ClawHub samples.

Full dev guide: Development

Documentation

Architecture Pipeline design, scoring logic, storage layer
API Reference All 30+ endpoints with schemas and examples
Detection Rules All 30 rules with patterns and false positive guidance
Threat Campaigns Campaign tracking, ClawHavoc case study
CLI Reference Every command with flags and examples
Deployment pip, Docker, nginx, production config
Development Adding rules, endpoints, testing, conventions

What's New in v0.3.1

Extensibility — YAML DSL for custom rules, rule testing framework, plugin system, ML-based risk scoring.

Infrastructure — PostgreSQL backend support, Redis caching layer, GitLab CI and Azure DevOps templates.

Security & Compliance — Immutable audit logging, role-based access control (RBAC), CI security scanning with SBOM.

Operations — Scheduled background scanning, multi-channel notifications (Slack, email, webhooks), git diff scanning.

User Experience — Dashboard analytics with trend charts, Rich TUI for interactive terminal usage.

Registry Integrationmalwar crawl command to browse, search, and scan skills directly from ClawHub. Also supports scanning any remote SKILL.md by URL.

Emerging Agentic Threats — Detection for the threat classes Unit 42 disclosed in June 2026: agentic affiliate injection and pump-and-dump / front-running (MALWAR-FRAUD-*), plus scanner-evasion via file-size inflation (MALWAR-EVADE-*) — the techniques that bypassed ClawScan and VirusTotal. Both the rule engine and the ML risk scorer were extended to cover them.

1,596 tests | 30 detection rules | 82% coverage


MIT License — Copyright (c) 2026 Veritas Aequitas Holdings LLC.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

malwar-0.4.0.tar.gz (1.9 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

malwar-0.4.0-py3-none-any.whl (279.7 kB view details)

Uploaded Python 3

File details

Details for the file malwar-0.4.0.tar.gz.

File metadata

  • Download URL: malwar-0.4.0.tar.gz
  • Upload date:
  • Size: 1.9 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for malwar-0.4.0.tar.gz
Algorithm Hash digest
SHA256 fdd9f8a9331b72ded243e79b76245a4ebc6c729b4cc89173efaabfab62d929f1
MD5 42f953d2a4e47b8f348a41c55939ed2d
BLAKE2b-256 765b456aa52f5f1e5f385564fc0cdd1db49f2ce388ded210e23bbd8315f1097c

See more details on using hashes here.

Provenance

The following attestation bundles were made for malwar-0.4.0.tar.gz:

Publisher: publish-pypi.yml on Ap6pack/malwar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file malwar-0.4.0-py3-none-any.whl.

File metadata

  • Download URL: malwar-0.4.0-py3-none-any.whl
  • Upload date:
  • Size: 279.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for malwar-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9ba77f7282ad175c1485a37bfc58cbba71abc9d8c73d526108db81d00e909624
MD5 0a3fe45d3273edb50966069fc851ec7d
BLAKE2b-256 aa36e121f3e0de1bf68513b9922c949a91c48cea64ac3cff198c2a2a3f6662db

See more details on using hashes here.

Provenance

The following attestation bundles were made for malwar-0.4.0-py3-none-any.whl:

Publisher: publish-pypi.yml on Ap6pack/malwar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page