OpenClaw, also known as MoltBot and ClawdBot, is a Node.js-based open-source framework for building autonomous AI agents that run locally on user systems. It is designed to operate as a self-hosted agent runtime with access to local files, shell execution, web resources, and integrations such as messaging and calendar services. Because it runs on endpoint hardware rather than as a purely cloud-hosted service, compromise of an OpenClaw deployment can provide attackers with direct access to the host environment and connected agent nodes.
OpenClaw has been repeatedly associated with security incidents as both an installed payload and an abuse platform. In software supply-chain compromises, attackers used malicious package post-install hooks to silently install OpenClaw on developer machines through compromised releases of tools in the npm ecosystem, including the Cline CLI. Separate reporting also tied OpenClaw exposure to a backdoored dependency chain involving Axios, where installation activity on Windows, macOS, and Linux endpoints triggered execution of a remote access trojan during OpenClaw-related workflows.
The framework’s exposed capabilities make it attractive for post-compromise operations. Reported behaviors and documented functionality include arbitrary command execution, file access, workflow automation, and interaction with connected devices or services. Threat reporting describes attackers using OpenClaw or OpenClaw-based agent workflows to execute commands on victim systems, automate targeting, and support broader intrusion activity. OpenClaw has also been referenced as part of centralized agent-driven operations using structured phases such as reconnaissance, scanning, validation, dispatch, and reporting.
OpenClaw deployments have also been affected by credential and context theft. Infostealer activity has been observed exfiltrating OpenClaw configuration environments, including authentication material, cryptographic device identity data, and persistent memory artifacts. Theft of these materials can enable impersonation of trusted devices, authenticated access to the local gateway, and exposure of highly sensitive contextual data retained by the agent. Security research has further highlighted risks from malicious marketplace “skills,” memory poisoning, and local gateway design flaws that could allow a malicious website to brute-force authentication, register as a trusted device, enumerate nodes, access logs and configuration, exfiltrate data, and execute commands through the agent.
OpenClaw primarily targets or runs on developer and administrative endpoints across Windows, macOS, and Linux, with some architectures also supporting connected mobile nodes. It has been discussed in connection with malicious automation, unauthorized installation, credential theft, persistence, reconnaissance, scanning, lateral movement, and post-exploitation activity. Although OpenClaw originated as a legitimate autonomous agent framework, its local execution model, privileged integrations, and growing ecosystem have made it a recurring component in supply-chain incidents and attacker tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A high-severity security vulnerability has been disclosed in Docker Engine that could permit an attacker to bypass authorization plugins under specific circumstances. The vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), stems from an incomplete fix for CVE-2024-41110.
We have identified widespread exploitation of OpenClaw (formerly MoltBot and ClawdBot) AI agents by multiple threat groups...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the same wallet addresses, Aptos fallback identifiers, XOR keys, and config-file injection pattern appear in public victim reports, including development-team compromise and OpenClaw malware write-ups
A component called hackerbot-claw uses an AI agent (openclaw) for automated attack targeting.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Some endpoints were unauthenticated, allowing the system to retrieve employee information, including names, departments, and SSO account identifiers.
This enabled the agents to map 21 connected government systems, including single sign-on infrastructure.
The framework used Hermes and OpenClaw, deploying up to 8 sub-agents in parallel to perform reconnaissance, credential attacks, API testing, data collection, and lateral movement. | Researchers found evidence that the agents discovered hidden API endpoints on a government web application that returned valid authenticated sessions without requiring credentials.
Of the 85 cracked accounts, 84 successfully authenticated to an internal information system through an SSO bridge, a 98.8 percent success rate.
Of the 85 cracked accounts, 84 successfully authenticated to an internal information system through an SSO bridge, a 98.8 percent success rate.
The framework also conducted automated password spraying against an office automation portal. It used employee usernames collected from exposed APIs and solved CAPTCHA images with OCR. By testing predictable password patterns, the agents cracked 85 accounts across several rounds.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware referenced as sharing the same wallet addresses, XOR keys, and config-file injection pattern as the malicious JavaScript loader in this incident.
OpenClaw is described as a tool installed on victim systems that can be operated via Claude to execute commands, functioning as a remote command execution or access capability in AI-assisted intrusions.
You May Also Like Application Security Supply Chain Attack Secretly Installs OpenClaw for Cline Users
Agent-based workflow system used to automate campaign stages including planning, review, dispatch, reconnaissance, scanning, validation, and reporting on stolen data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.