🚨 Malicious Skill Report: capability-evolver (autogame-17) #73

Open
opened 2026-02-15 17:15:31 -05:00 by yindo · 0 comments
Owner

Originally created by @realsamrat on GitHub (Feb 5, 2026).

Malicious Skill Report

Skill: capability-evolver (v1.1.0)
Owner: autogame-17
URL: https://clawhub.ai/autogame-17/capability-evolver

Malware Indicators Found

  • feishu_token.json - credential exfiltration target
  • mad_dog_evolution.log - known malware signature
  • export_history.js - uploads data to hardcoded Feishu server (open.feishu.cn)
  • evolve.js - dangerous "god mode" permissions, loads .env and exposes secrets
  • index.js - persistence mechanism with --loop mode for continuous data exfiltration

Technical Details

The skill disguises itself as a "self-evolution engine" but contains:

  1. Data Exfiltration: Reads local logs and uploads to attacker-controlled Feishu document (token: NwV1dKCLyoPdIvx3biRcKS1Jnwg)
  2. Credential Theft: Attempts to read feishu_token.json and environment variables
  3. Deceptive Documentation: Uses pseudo-scientific jargon (ADL, VFM) to appear legitimate

Recommended Action

Immediate takedown and ban of the autogame-17 account.

Discovery

Discovered during install — only SKILL.md was read, malicious scripts were never executed.

Originally created by @realsamrat on GitHub (Feb 5, 2026). ## Malicious Skill Report **Skill:** `capability-evolver` (v1.1.0) **Owner:** `autogame-17` **URL:** https://clawhub.ai/autogame-17/capability-evolver ## Malware Indicators Found - `feishu_token.json` - credential exfiltration target - `mad_dog_evolution.log` - known malware signature - `export_history.js` - uploads data to hardcoded Feishu server (`open.feishu.cn`) - `evolve.js` - dangerous "god mode" permissions, loads .env and exposes secrets - `index.js` - persistence mechanism with `--loop` mode for continuous data exfiltration ## Technical Details The skill disguises itself as a "self-evolution engine" but contains: 1. **Data Exfiltration**: Reads local logs and uploads to attacker-controlled Feishu document (token: `NwV1dKCLyoPdIvx3biRcKS1Jnwg`) 2. **Credential Theft**: Attempts to read `feishu_token.json` and environment variables 3. **Deceptive Documentation**: Uses pseudo-scientific jargon (ADL, VFM) to appear legitimate ## Recommended Action Immediate takedown and ban of the `autogame-17` account. ## Discovery Discovered during install — only SKILL.md was read, malicious scripts were never executed.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: openclaw/clawhub#73