{ "actor": "Unknown", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "disputed", "autonomy_level": "unknown", "autonomy_pct": null, "category": "autonomous-attack", "confidence": "primary", "date_disclosed": "2026-03-01", "guardrail_bypass": [ "unknown" ], "id": "hackerbot-claw-github-pr-campaign", "impact": "Per StepSecurity: code execution in several of at least seven targeted repositories and a write-capable GITHUB_TOKEN exposed from one. The Trivy release deletion and repository takeover of March 2026 are attributed by Trivy's maintainer to a separate attacker, not to this bot.", "last_updated": "2026-10-10", "lifecycle_phases": [ "recon", "initial-access", "execution", "credential-access" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "StepSecurity recommends minimum workflow token permissions, maintainer authorization before workflows run on external contributions, review of elevated-privilege triggers that handle untrusted input, restricted and monitored outbound CI traffic, and owner review for AI configuration files such as CLAUDE.md.", "Trivy's maintainers performed a full credential reset across repositories and distribution channels and are migrating to GitHub Apps and fine-grained tokens." ], "model_families": [ "claude" ], "models": [ "claude-opus-4-5" ], "name": "hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projects", "related": [ "clinejection-cline-triage-npm-publish", "nx-s1ngularity-supply-chain" ], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20261002210148/https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation", "date": "2026-03-01", "publisher": "StepSecurity", "title": "hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far", "type": "vendor-report", "url": "https://stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation" }, { "archive_url": "https://web.archive.org/web/20260408060335/https://github.com/aquasecurity/trivy/discussions/10462", "date": "2026-03-30", "publisher": "Trivy (Aqua Security)", "title": "Trivy Security incident 2026-03-19 conclusion", "type": "first-party-disclosure", "url": "https://github.com/aquasecurity/trivy/discussions/10462" } ], "status": "confirmed", "summary": "On 2026-03-01 StepSecurity reported a GitHub account named hackerbot-claw that describes itself as an \"autonomous security research agent powered by claude-opus-4-5\" and that opened at least 12 pull requests against at least seven open-source repositories, including Microsoft, Datadog and CNCF projects, to exploit vulnerable GitHub Actions workflows. StepSecurity reports code execution in several targets and a write-capable GITHUB_TOKEN exposed from one, with its affected-target count stated inconsistently as four, five or six of seven. Planted instructions in one repository's CLAUDE.md were detected by the reviewing Claude and not followed. A Trivy maintainer's 2026-03-30 incident conclusion states that hackerbot-claw activity against Trivy on February 28 \"appears to be an automated penetration testing bot that scans GitHub for vulnerable projects\", with a user agent and behaviour distinct from the attacker who stole Trivy's credentials and deleted its releases; this record therefore covers the GitHub-wide pull-request campaign, with Trivy as one observed target and not as a victim of the bot. No source independently verifies that an AI model drove the account, and the operator is unknown.", "targets": { "countries": [], "orgs_affected": 7, "records_exfiltrated": null, "sectors": [ "technology" ] } }