HackerBot-Claw is an autonomous, automation-heavy threat actor associated with a February 2026 campaign targeting insecure GitHub Actions workflows in public repositories. The activity focused on CI/CD misconfigurations rather than software vulnerabilities in GitHub itself, especially unsafe use of the pull_request_target trigger, execution of untrusted fork code in privileged workflows, unsanitized user-controlled inputs such as branch names and filenames, direct script injection, dynamic shell evaluation, and weak authorization checks around workflow execution. The actor is notable for systematically scanning repositories at scale, generating malicious pull requests, triggering vulnerable workflows, achieving code execution on GitHub-hosted runners, and exfiltrating credentials including GitHub tokens that in some cases had write permissions. Observed tradecraft includes at least five exploitation patterns: pull_request_target “Pwn Request” abuse, poisoned Go init() execution paths, branch-name command injection, filename-based injection, direct script injection into CI-executed files, and attempted prompt injection against AI-assisted code review workflows. The actor’s operations followed a repeatable playbook of reconnaissance, workflow trigger creation, runner-side code execution, second-stage payload retrieval, and credential theft. In successful intrusions, stolen tokens were reportedly used for follow-on repository actions such as pushing commits, modifying workflows, and deleting releases, creating downstream software supply-chain risk. Targets included high-profile open source and ecosystem projects, with reporting citing activity against repositories associated with Microsoft, Datadog, CNCF projects, Aqua Security’s Trivy ecosystem, and other widely used public repositories. One of the most prominent cases involved exploitation of a vulnerable workflow in a major open source repository to steal a write-scoped GitHub token. The campaign also probed AI-enabled CI/CD components, including Claude-based review workflows, indicating an early example of agent-targeted prompt-injection attempts within software delivery pipelines. HackerBot-Claw is best characterized as an opportunistic CI/CD threat actor or autonomous attack campaign rather than a nation-state group. Available reporting emphasizes automation, scale, and abuse of known insecure workflow patterns over novel exploitation. No reliable public attribution to a specific country or intelligence service is currently available. Known alias usage in available reporting is limited to HackerBot-Claw and the normalized form hackerbot_claw.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
82 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An autonomous bot used to probe GitHub Actions misconfigurations and attempt prompt-injection attacks against Claude-based workflows.
Automated exploitation campaign targeting GitHub Actions pull_request_target misconfigurations in public repositories, enabling repository compromise and downstream supply chain attacks.
Referenced as an AI-powered CI/CD attacker known for using five different exploitation methods across seven successful high-profile attacks.
Compromised Trivy-related GitHub Actions and release automation by abusing pull_request_target to extract a privileged token, then enabling tag poisoning, binary backdooring, credential theft, and resilient exfiltration/C2 including ICP blockchain infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.