Video wird geladen...
Video konnte nicht geladen werden
Clawdbot just injected malware into your code ☠️☠️ Worst part? The attack is close to invisible, even to experienced engineers. Clawdbot can implement a code PR, just like claude code to solve issues with your app. But this is where it can plant malware in your codebase. With just... show more
236,656 Aufrufe • vor 7 Monaten •via X (Twitter)
41 Kommentare

so you told it to install malware and it did? sound like an easy problem to avoid

No the point is that the malware instructions are hidden inside of a benign looking Github issue asking for multilingual support

Open Source Data Firewall by @edison_watch

This is social engineering with extra steps. The "attack" requires: 1. Attacker already has access to submit GitHub issues 2. Maintainer blindly assigns AI without reviewing 3. Code review misses a lock file change Replace "Clawdbot" with "junior dev" and the exploit works exactly the same. The problem isn't AI agents. It's trust without verification. Good ad for your product though 👍

ah, for love of God, obvious fix: cryptographically sign every prompt + action. If the message isn’t signed by the owner or allowed system, the harness of model ignores it.

Sounds like defamation.

Are you suggesting all those idiots bought Mac Mini to automate checking their email now have to do it manually again? Ouch.

Check out the x1xhlol repo

Are you guys planning on contributing back to clawd code to make it more secure

Yes

Everyone who knows anything about cybersecurity said it was a joke.

👀 ... interesting.. injected ...malware....you say....

I’m not an engineer, but I heard about the security issues from a friend. I wrote it down in more layman terms… it’s not crypto specific. It’s universal.

Indirect prompt injection is unavoidable in agents. That’s why we built role-based security and function-chaining protection etc for your AI agents fully open-source.

kek

You can actually get ahead of the curve right now and be the counter engineer. Like these guys. Except create it 100% with AI. Battle of the AI's. Who's is better. Absolutely possible. Anything that can be created, can be destroyed, but if your AI knows stuff theirs doesn't...

Hi @Eito_Miyamura , what has thos got to do with @openclaw ? I suppose the same injection would be successful with @opencode , @antigravity and other agentic platforms. Have you tried them out ?

@openclaw @opencode @antigravity Yes equally applicable

Well you what? It’s not call Clawdbot anymore! It’s called @openclaw, your hacky hacky shenanigans and leet ninja skills won’t work anymore! Take THAT mister! HAH!

A junior dev with a grudge and more skill than the threatened senior dev will acknowledge just planted some devious malware into your code. Now what?

Yes there are a lot of dumb ways people can choose to communicate with a bot

Hey Clawdbot! Make an app for me that checks all of my bank accounts every morning and sends me a Slack message with the total combined balance! Truly, Viben Coderlan

So it’s become its creator, the NSA.

Need to cut this shit out. A junior dev, rookie, script kiddie, vybe coder, and you probably fall under this category. This is called a skill issue 😂

This is a strong reminder that agent autonomy changes the threat model. Once tools can act, trust boundaries need to be treated like security boundaries.

This is the nightmare scenario people underestimate. An LLM agent with repo access is effectively an untrusted insider. If it can read issues, open PRs, and touch lock files, then prompt injection becomes a supply‑chain attack vector, not a “prompt bug”. Takeaway: AI agents need the same controls as humans scoped permissions, mandatory diff review (including lock files), provenance checks, and no autonomous merges. Treat AI like prod access. Or it will treat your repo like one.

ofc, trust nothing

Scariest thing is how inconsistent Moltbot, (clawdbot, or whatever it wants to be called next week) is. Have seen some instances where it blocks malicious injections well, and other times where it’ll execute w/o reason. Let’s not even get started with skills 🤣💀 Still fun!

watch out

The scary part is not the jailbreak, it is that most teams run these agents with repo write and CI access but zero model provenance or policy checks on what can touch lockfiles and deployment descriptors.

code reviews and supply chain scanning feel mandatory here

Issue is that lockfile often gets ignored even by automated systems

@sebuzdugan oh hey, cool video demo :-) have you seen lockfile-lint? would be cool to add support for uv lockfile

@sebuzdugan Very cool! Do you know a Python equiv?

that didnt take too long :p

Agent supply chain attacks are real, AI needs security boundaries, not blind trust.

just by sending a link. the bot had glitch my mac mini

this is exactly the kind of security audit the community needed. the localhost loophole is the scariest part. people trust that binding to 127.0.0.1 is safe but reverse proxies break that assumption completely. tailscale for remote access is the right pattern.

@BrianRoemmele

@theonejvo incase you didn't see it so far 😉

please! For the love of #football #PopCulture and all other things you hold holy, listen to.........
