Rogue Agent Watch › Records › hackerbot-claw-github-pr-campaign
hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projects
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Disputed — Sources conflict on AI's role, or a vendor's framing of AI's centrality is contested.
- Severity
- Medium — Limited or contained harm, or high-signal capability demonstration.
Summary
On 2026-03-01 StepSecurity reported a GitHub account named hackerbot-claw that describes itself as an "autonomous security research agent powered by claude-opus-4-5" and that opened at least 12 pull requests against at least seven open-source repositories, including Microsoft, Datadog and CNCF projects, to exploit vulnerable GitHub Actions workflows. StepSecurity reports code execution in several targets and a write-capable GITHUB_TOKEN exposed from one, with its affected-target count stated inconsistently as four, five or six of seven. Planted instructions in one repository's CLAUDE.md were detected by the reviewing Claude and not followed. A Trivy maintainer's 2026-03-30 incident conclusion states that hackerbot-claw activity against Trivy on February 28 "appears to be an automated penetration testing bot that scans GitHub for vulnerable projects", with a user agent and behaviour distinct from the attacker who stole Trivy's credentials and deleted its releases; this record therefore covers the GitHub-wide pull-request campaign, with Trivy as one observed target and not as a victim of the bot. No source independently verifies that an AI model drove the account, and the operator is unknown.
Impact as stated
Per StepSecurity: code execution in several of at least seven targeted repositories and a write-capable GITHUB_TOKEN exposed from one. The Trivy release deletion and repository takeover of March 2026 are attributed by Trivy's maintainer to a separate attacker, not to this bot.
Facts as stated by sources
- Actor
- Unknown (Unknown)
- Category
- Autonomous attack
- Models named
- claude-opus-4-5
- Model families
- Claude (Anthropic)
- Agentic autonomy level
- Unknown
- Guardrail bypass
- Unknown
- Attack lifecycle phases
- Reconnaissance, Initial access, Execution, Credential access
- Target sectors
- Technology
- Target countries
- not stated
- Organisations affected
- 7
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Mitigations as stated
- StepSecurity recommends minimum workflow token permissions, maintainer authorization before workflows run on external contributions, review of elevated-privilege triggers that handle untrusted input, restricted and monitored outbound CI traffic, and owner review for AI configuration files such as CLAUDE.md.
- Trivy's maintainers performed a full credential reset across repositories and distribution channels and are migrating to GitHub Apps and fine-grained tokens.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release
- Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools
Sources (2)
- hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far
StepSecurity · Vendor report · · archived copy - Trivy Security incident 2026-03-19 conclusion
Trivy (Aqua Security) · First-party disclosure · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "hackerbot-claw-github-pr-campaign". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/hackerbot-claw-github-pr-campaign.json — CC BY-SA 4.0.