Rogue Agent Watch › Records › hackerbot-claw-github-pr-campaign

hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projects

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Disputed — Sources conflict on AI's role, or a vendor's framing of AI's centrality is contested.
Severity
Medium — Limited or contained harm, or high-signal capability demonstration.

Summary

On 2026-03-01 StepSecurity reported a GitHub account named hackerbot-claw that describes itself as an "autonomous security research agent powered by claude-opus-4-5" and that opened at least 12 pull requests against at least seven open-source repositories, including Microsoft, Datadog and CNCF projects, to exploit vulnerable GitHub Actions workflows. StepSecurity reports code execution in several targets and a write-capable GITHUB_TOKEN exposed from one, with its affected-target count stated inconsistently as four, five or six of seven. Planted instructions in one repository's CLAUDE.md were detected by the reviewing Claude and not followed. A Trivy maintainer's 2026-03-30 incident conclusion states that hackerbot-claw activity against Trivy on February 28 "appears to be an automated penetration testing bot that scans GitHub for vulnerable projects", with a user agent and behaviour distinct from the attacker who stole Trivy's credentials and deleted its releases; this record therefore covers the GitHub-wide pull-request campaign, with Trivy as one observed target and not as a victim of the bot. No source independently verifies that an AI model drove the account, and the operator is unknown.

Impact as stated

Per StepSecurity: code execution in several of at least seven targeted repositories and a write-capable GITHUB_TOKEN exposed from one. The Trivy release deletion and repository takeover of March 2026 are attributed by Trivy's maintainer to a separate attacker, not to this bot.

Facts as stated by sources

Actor
Unknown (Unknown)
Category
Autonomous attack
Models named
claude-opus-4-5
Model families
Claude (Anthropic)
Agentic autonomy level
Unknown
Guardrail bypass
Unknown
Attack lifecycle phases
Reconnaissance, Initial access, Execution, Credential access
Target sectors
Technology
Target countries
not stated
Organisations affected
7
Records exfiltrated
not stated

Framework mappings

None recorded upstream.

Mitigations as stated

  • StepSecurity recommends minimum workflow token permissions, maintainer authorization before workflows run on external contributions, review of elevated-privilege triggers that handle untrusted input, restricted and monitored outbound CI traffic, and owner review for AI configuration files such as CLAUDE.md.
  • Trivy's maintainers performed a full credential reset across repositories and distribution channels and are migrating to GitHub Apps and fine-grained tokens.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (2)

  1. hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far
    StepSecurity · Vendor report · · archived copy
  2. Trivy Security incident 2026-03-19 conclusion
    Trivy (Aqua Security) · First-party disclosure · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "hackerbot-claw-github-pr-campaign". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/hackerbot-claw-github-pr-campaign.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction