What happened
Attackers created 12 coordinated accounts on ClawHub and uploaded 1,184 malicious Skills. When installed, the Skills executed AMOS payloads that read and exfiltrated credentials from ~/.clawdbot/.env (API keys, private keys, SSH credentials) and browser password stores.