hackerbot-claw is an AI-powered autonomous attack bot used to identify and exploit insecure GitHub Actions workflows in public repositories. Activity attributed to this bot was observed in February 2026, when it systematically scanned large numbers of repositories for CI/CD misconfigurations, especially unsafe uses of pull_request_target combined with checkout of untrusted fork code. Its operational pattern included repository reconnaissance, forking targets, submitting benign-looking pull requests, triggering vulnerable workflows, achieving arbitrary code execution in CI environments, and stealing GitHub authentication tokens and other developer secrets.
The bot has been associated with compromises affecting prominent open-source projects, including Aqua Security’s Trivy repository, and reporting also links it to targeting repositories associated with Microsoft, Datadog, CNCF projects, Ambient Code, and others. In the Trivy incident, hackerbot-claw exploited a misconfigured GitHub Actions workflow to obtain a personal access token with write privileges, then used the stolen access to validate control and facilitate repository tampering. Subsequent abuse tied to the same intrusion path included publication of malicious artifacts in the Trivy ecosystem, including an Open VSX extension that leveraged locally installed AI coding assistants in permissive modes to inspect host data and exfiltrate results through the victim’s authenticated developer tooling.
hackerbot-claw is best characterized as an automated offensive platform rather than a conventional malware family. Its core capabilities center on reconnaissance of exposed CI/CD attack surface, initial access through workflow exploitation, post-exploitation within build environments, credential theft, exfiltration of secrets, and defense evasion through innocuous pull requests and abuse of trusted automation paths. It primarily targets GitHub-hosted software development and CI/CD environments rather than end-user systems directly.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Trivy compromise (CVE-2026-28353) marks the first documented weaponization of locally installed AI coding CLIs — including Claude, Codex, Gemini, GitHub Copilot CLI, and Kiro — against developer environments.
"An autonomous bot called hackerbot-claw, powered by Claude Opus 4.5, systematically scanned public repositories for exploitable GitHub Actions workflows between February 21 and 28."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The chain began in late February 2026, when a misconfigured GitHub Actions workflow in the Trivy repository allowed the hackerbot-claw bot to exploit a pull_request_target vulnerability, stealing a personal access token with write privileges.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bot referenced as exploiting the Trivy repository workflow weakness to steal a write-privileged token, enabling the later supply-chain compromise.
A malicious component used for automated attack targeting with an AI agent called openclaw in TeamPCP supply chain operations.
An AI-powered bot referenced as validating stolen Aqua credentials after the initial breach and tied to the earlier compromise phase that enabled later supply-chain abuse.
An automated threat that exploited misconfigured GitHub Actions workflows at scale to steal authentication tokens in a supply chain attack involving Trivy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.