Threat actors abused the popularity of OpenClaw (an open-source, agentic AI framework that can browse the web and execute commands) by publishing fake Windows installers on GitHub and getting them surfaced prominently in Bing’s AI-powered search results. Users searching for “OpenClaw Windows” were directed to a malicious GitHub organization/repository (e.g., openclaw-installer) that delivered information-stealing malware and GhostSocks, with Huntress reporting it identified the activity after a user downloaded and executed the installer; the malicious GitHub assets were subsequently removed. The campaign’s effectiveness relied on trust signals—GitHub hosting, plausible organization naming, and AI search ranking—illustrating how quickly criminals can weaponize new, high-interest developer tools.
Separate from the installer campaign, security commentary highlighted broader enterprise risk from unauthorized agentic AI on endpoints: OpenClaw’s local, Node.js-based design and “skills” model can bypass procurement controls and expand system-level access, creating visibility and governance gaps for SecOps and threat hunting. Consumer-facing coverage also pointed to the emergence of NanoClaw as a smaller-codebase alternative positioned as potentially safer, emphasizing isolation/sandboxing as a key control when experimenting with agentic AI that can take real actions (email, calendar, payments, device control).

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Canary released a threat-hunting analysis focused on unmanaged OpenClaw use, malicious skills spawning shells, and credential access or exfiltration behaviors. The guidance framed OpenClaw as a shadow-IT and post-compromise risk and recommended detections and hardening controls.
Security reporting described an influx of malicious OpenClaw skills on the public ClawHub registry, including claims that a top-downloaded skill was actually a disguised infostealer. This expanded concern from fake installers to the broader OpenClaw extension ecosystem.
ZDNET reported on NanoClaw, an open-source personal AI agent designed with per-agent container isolation and a smaller codebase as a safer alternative to OpenClaw. The coverage also highlighted OpenClaw's history of security issues, including prompt-injection exposure, compromised skills, and exposed instances.
After the malicious repositories and associated accounts were reported, GitHub removed the original "openclaw-installer" repo and related entities. Reporting indicates the infrastructure was taken down around February 10.
Huntress uncovered multiple additional GitHub organizations and accounts tied to the fake OpenClaw installer campaign and reported them to GitHub. The activity showed the campaign extended beyond a single repository.
Victims who followed the fake GitHub installer workflow received malware instead of OpenClaw, including Vidar infostealer and GhostSocks proxy malware on Windows, while macOS instructions led to content associated with Atomic Stealer. The Windows chain used Rust-based loaders and in-memory execution to deploy payloads.
On February 9, Huntress observed Bing's AI-enhanced search results recommending a newly created GitHub repository for "OpenClaw Windows," directing users to the malicious installer. This search poisoning gave the fake repo credibility and increased the likelihood of victim downloads.
Threat actors created fake GitHub organizations and repositories, including "openclaw-installer," to impersonate OpenClaw and host trojanized Windows installers. The repositories were reportedly created around early February and were designed to look legitimate by reusing code from Cloudflare's moltworker project.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 38 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
7 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceredcanary.com
Open sourcezdnet.com
Open sourcego.theregister.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.