🗾Stalecollected in 84m

Attack Group Targets OpenClaw with Fake Apps

Attack Group Targets OpenClaw with Fake Apps
PostLinkedIn
🗾Read original on ITmedia AI+ (日本)

💡New OpenClaw-targeted malware via fake AI sites exposed—bolster your defenses now (ThreatBook intel).

⚡ 30-Second TL;DR

What Changed

ThreatBook reports attack group abusing AI apps to target OpenClaw

Why It Matters

Elevates cybersecurity risks for AI tool users, necessitating stricter app verification and monitoring.

What To Do Next

Download ThreatBook's OpenClaw threat report and scan environments for matching IOCs.

Who should care:Enterprise & Security Teams

Key Points

  • ThreatBook reports attack group abusing AI apps to target OpenClaw
  • Deploys fake websites, articles, and browser extensions for user deception
  • Infiltrates devices via prompted operations to steal confidential data

🧠 Deep Insight

Background and context from public sources — not the original article. 8 sources cited.

🔑 Enhanced Key Takeaways

  • CVE-2026-25253 is a high-severity (CVSS 8.8) one-click remote code execution vulnerability in OpenClaw, exploitable via cross-site WebSocket hijacking even on localhost instances, discovered by Mav Levin and patched in version 2026.1.29[1][2][3].
  • ClawHub registry contains over 800 malicious skills (about 20% of total), including those delivering Atomic macOS Stealer (AMOS), with one account 'hightower6eu' uploading 354 malicious packages[1][2].
  • Over 42,000 OpenClaw instances were publicly exposed internet-wide, with 5,194 verified vulnerable including authentication bypass conditions[1].

🛠️ Technical Deep Dive

  • CVE-2026-25253 exploits CWE-669 via a two-stage attack: malicious page redirects to OpenClaw Gateway with harmful gatewayUrl parameter to leak auth token over unvalidated WebSocket (ws://localhost:18789), then second stage fetches token, validates signature, connects via WebSocket, and executes arbitrary commands on AI agents[1][4].
  • Attack impacts local instances by using victim's browser as pivot; WebSocket server lacks Origin header validation, enabling cross-site hijacking for token exfiltration and operator-level API access to read files, change config, and run system commands[2][3][4].
  • Additional vulnerabilities include CVE-2026-26322 (SSRF in Gateway, CVSS 7.6), CVE-2026-26319 (missing Telnyx webhook auth, CVSS 7.5), CVE-2026-26329 (path traversal in browser upload), and another SSRF in image tool (GHSA-56f2-hvwg-5743)[5].

🔮 Future ImplicationsAI analysis grounded in cited sources

Increased targeting of agentic AI tools like OpenClaw due to exposed instances and supply chain risks
Tens of thousands of misconfigured public instances combined with 20% malicious skills in ClawHub enable widespread exploitation by threat actors[1][5].
Demand for stricter ClawHub vetting and local deployment hardening
Low publication barriers allowed hundreds of malicious skills, while WebSocket flaws highlight need for origin validation and reverse proxies[1][2].

Timeline

2026-01
CVE-2026-25253 disclosed by Mav Levin of depthfirst, enabling one-click RCE via WebSocket hijacking
2026-01-30
OpenClaw releases version 2026.1.29 patching CVE-2026-25253 and two command injection flaws
2026-01-25 to 2026-01-31
Publicly exposed OpenClaw instances surge from 1,000 to over 21,000 per Censys data
2026-02
Endor Labs discloses six new vulnerabilities including SSRF and path traversal bugs, patched by OpenClaw
2026-02-18
Endor Labs publishes report on seven OpenClaw vulnerabilities
2026-03
ThreatBook identifies attack group targeting OpenClaw with fake apps, sites, and extensions
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: ITmedia AI+ (日本)

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.