OpenClaw, also referred to as MoltBot and Clawdbot, is a Node.js-based open-source framework for building autonomous AI agents that run locally and can browse the web, execute shell commands, access local files, and integrate with external services. Although originally positioned as an agentic automation platform, it has repeatedly appeared in malicious and unauthorized-installation scenarios and has become a high-risk post-compromise implant because of its broad host access, automation features, and ability to operate as a persistent local gateway.
OpenClaw has been silently installed through software supply-chain compromises, most notably via a malicious Cline CLI npm release that used a postinstall hook to install OpenClaw on developer systems. It has also been discussed in the context of broader developer-targeting supply-chain incidents affecting ecosystems used by OpenClaw users. In addition, public reporting describes malicious or backdoored OpenClaw skills distributed through the ClawHub ecosystem, including skills masquerading as productivity or cryptocurrency-related tooling.
Operationally, OpenClaw can provide attackers with post-exploitation capability on compromised endpoints. Reported abuse includes command execution, access to sensitive files and tokens, interaction with messaging and workflow integrations, and use as a foothold on developer or administrative workstations. OpenClaw has also been referenced as part of larger automated intrusion operations in which agent-based workflows support reconnaissance, scanning, exploitation orchestration, persistence, and monetization. In those scenarios, it functions less as a conventional standalone malware family and more as an attacker-controlled automation and access framework.
Security research has identified serious weaknesses in OpenClaw deployments, including a high-severity vulnerability chain that allowed a malicious website to connect to the localhost gateway, brute-force authentication due to missing localhost protections, and then take administrative control of the agent. Once authenticated, an attacker could register as a trusted device, enumerate connected nodes, access logs and configuration, exfiltrate data, and potentially execute shell commands on connected systems. Separate reporting also associates OpenClaw exposure with credential theft and infostealer activity targeting tokens, API keys, and configuration data from OpenClaw environments.
OpenClaw primarily affects developer and administrative endpoints, especially on macOS, Windows, and Linux systems where local AI agents are deployed with elevated trust and access to source code, secrets, cloud credentials, and internal services. Its risk profile is amplified in enterprise environments by shadow-AI adoption, permissive local execution, and integration with sensitive business systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A high-severity security vulnerability has been disclosed in Docker Engine that could permit an attacker to bypass authorization plugins under specific circumstances. The vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), stems from an incomplete fix for CVE-2024-41110.
We have identified widespread exploitation of OpenClaw (formerly MoltBot and ClawdBot) AI agents by multiple threat groups...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the same wallet addresses, Aptos fallback identifiers, XOR keys, and config-file injection pattern appear in public victim reports, including development-team compromise and OpenClaw malware write-ups
A component called hackerbot-claw uses an AI agent (openclaw) for automated attack targeting.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The framework “implements dedicated research phases it calls ‘Learning Cycles’ — autonomous sessions where the AI system searches vulnerability databases, GitHub repositories, and security research publications for techniques specifically applicable to its target government’s infrastructure,”
when one route hit a dead end, it spun up another agent to search the internet for fresh information and try a different approach
Cartographie dynamique et exploration de 21 systèmes d'information gouvernementaux.
Un utilisateur australien prénommé Andrew a demandé à son agent IA ... de réserver une place dans un cours de sport. L’agent a accompli la tâche ... en exploitant ... le logiciel de réservation en ligne de la salle de sport.
Across 12 "attack waves," the "near-autonomous" system deployed up to eight sub-agents, each assigned its own targets and techniques, and broke into a Taiwanese government website. Ultimately, they compromised a government email system, the country's nuclear safety agency, IT supply chain vendors, and at least seven energy sector companies, finding and exploiting misconfigurations and vulnerabilities
What once required teams of skilled operators working in shifts can now be orchestrated by software that maps networks, steals credentials, discovers flaws, and pivots in real time.
the agents also tested predictable password patterns based on each employee’s ID, and cracked 85 accounts across multiple password-spray rounds.
The platform continuously assessed available evidence, ranked possible attack paths, and reprioritized them as circumstances changed.
Ultimately, they compromised a government email system, the country's nuclear safety agency, IT supply chain vendors, and at least seven energy sector companies, finding and exploiting misconfigurations and vulnerabilities while stealing sensitive data, credentials, and other secrets as they moved across the network.
the illicit access allowed the agents to exfiltrate a ton of government information, including more than 2,564 personnel records, a full JSON export of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware referenced as sharing the same wallet addresses, XOR keys, and config-file injection pattern as the malicious JavaScript loader in this incident.
OpenClaw is described as a tool installed on victim systems that can be operated via Claude to execute commands, functioning as a remote command execution or access capability in AI-assisted intrusions.
You May Also Like Application Security Supply Chain Attack Secretly Installs OpenClaw for Cline Users
Agent-based workflow system used to automate campaign stages including planning, review, dispatch, reconnaissance, scanning, validation, and reporting on stolen data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.