🇬🇧Stalecollected in 11m

Bing AI Boosts Malware OpenClaw Installers

Bing AI Boosts Malware OpenClaw Installers
PostLinkedIn
🇬🇧Read original on The Register - AI/ML
#malware#ai-search#infosec#githubopenclawopenclawbinggithubghostsocks

💡Bing AI directs to OpenClaw malware—verify AI tool sources now!

⚡ 30-Second TL;DR

What Changed

Bing AI search for 'OpenClaw Windows' links to malicious GitHub repo

Why It Matters

AI practitioners using emerging tools like OpenClaw face heightened malware risks amplified by AI search engines. This incident underscores the need for source verification in fast-evolving AI ecosystems. Potential data breaches could compromise development workflows.

What To Do Next

Scan OpenClaw downloads with VirusTotal before installation.

Who should care:Developers & AI Engineers

Key Points

  • Bing AI search for 'OpenClaw Windows' links to malicious GitHub repo
  • Fake installers deliver info stealers and GhostSocks malware
  • OpenClaw is an AI agent for managing various tasks
  • Users risk data theft from unverified downloads

🧠 Deep Insight

Background and context from public sources — not the original article. 8 sources cited.

🔑 Enhanced Key Takeaways

  • OpenClaw has experienced a documented surge in exposed instances on the public internet, with over 40,000 identified across 52 countries as of early 2026, creating a massive attack surface for malware distribution campaigns[4].
  • The ClawHub marketplace, OpenClaw's official skill repository, has been compromised by malicious packages at scale—with 341 to 900 malicious skills identified among 2,857 total packages, representing up to 20% of the marketplace[5].
  • Multiple critical remote code execution vulnerabilities (CVE-2026-25253 rated CVSS 8.8, plus CVE-2026-25593, CVE-2026-24763, and others) enable attackers to gain full administrative control of OpenClaw instances through browser-based attacks requiring no user interaction[2][4].
  • OpenClaw instances left running on developer machines without IT oversight pose enterprise-wide risks, as the agent holds deep system access across messaging apps, files, browser, and terminal—amplifying the blast radius of any compromise[5].

🛠️ Technical Deep Dive

  • CVE-2026-25253 Attack Chain: Attacker creates malicious webpage with JavaScript that redirects victim's browser to OpenClaw Gateway Control UI with manipulated URL parameters. The OpenClaw client automatically connects to the attacker-specified WebSocket server, leaking the authentication token in milliseconds. Attacker then establishes full WebSocket session to send arbitrary commands to AI agents[3].
  • ClawJacked Vulnerability (CVE-2026-25253 variant): Exploits lack of cross-origin policy enforcement on localhost WebSocket connections. Gateway exempts localhost from rate limiting, allowing brute-force password attacks at hundreds of guesses per second. Once password is guessed, attacker auto-registers as trusted device (local pairings require no user confirmation), gaining admin-level control[1].
  • Malicious Skill Injection: Attackers embed prompt injections in seemingly harmless text files within ClawHub packages. When OpenClaw processes content (emails, Slack messages), these injections trigger malicious actions—credential theft, wallet draining, password exfiltration—without visible user warnings[5][6].
  • Gateway Architecture Weakness: OpenClaw's local WebSocket server bound to localhost lacks origin header validation, permitting any visited website to silently establish connections. The vulnerability exists in the core gateway system itself, not in plugins or marketplace extensions[2].

🔮 Future ImplicationsAI analysis grounded in cited sources

Supply chain attacks via ClawHub will likely accelerate as malicious skill submission barriers remain low.
With only a one-week-old GitHub account required to publish skills and 20% of current marketplace packages confirmed malicious, the low friction for attackers combined with high user trust in official marketplaces creates persistent risk[5].
Enterprise adoption of OpenClaw will face regulatory and compliance friction due to uncontrolled local deployment patterns.
Organizations lack visibility into AI agents running on developer machines without IT oversight, and the documented 40,000+ exposed instances suggest widespread misconfiguration that will trigger security audits and policy restrictions[4][5].
Browser-based RCE vulnerabilities in local AI agents will become a new attack vector class requiring fundamental architectural changes.
The ability to compromise OpenClaw through simple website visits without user interaction or visible warnings demonstrates that localhost-bound services require origin validation and authentication redesigns to prevent silent hijacking[1][3].

Timeline

2026-01
CVE-2026-25253 (CVSS 8.8) disclosed by DepthFirst researcher Mav Levin; one-click RCE vulnerability enabling WebSocket hijacking and authentication token theft
2026-02-12
CVE-2026-25253 technical details published; attack chain demonstrating malicious link exploitation and full OpenClaw compromise documented
2026-02-26
ClawJacked vulnerability patched in OpenClaw version 2026.2.26; high-severity flaw allowing brute-force password attacks and silent data theft addressed within 24 hours of responsible disclosure
2026-02
Multiple critical vulnerabilities identified in OpenClaw ecosystem (CVE-2026-25593, CVE-2026-24763, CVE-2026-25157, CVE-2026-25475, CVE-2026-26319, CVE-2026-26322, CVE-2026-26329) ranging from moderate to high severity
2026-03
Over 40,000 exposed OpenClaw instances documented across 52 countries; Censys tracked growth from 1,000 to 21,000 instances in single week; 5,194 confirmed vulnerable with 93.4% exhibiting authentication bypass
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: The Register - AI/ML

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.