Loading video...

Video Failed to Load

Go Home

Clawdbot just injected malware into your code โ˜ ๏ธโ˜ ๏ธ Worst part? The attack is close to invisible, even to experienced engineers. Clawdbot can implement a code PR, just like claude code to solve issues with your app. But this is where it can plant malware in your codebase. With just...

236,656 views โ€ข 7 months ago โ€ขvia X (Twitter)

41 Comments

EllioTrades's profile picture
EllioTrades7 months ago

so you told it to install malware and it did? sound like an easy problem to avoid

Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)'s profile picture
Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)7 months ago

No the point is that the malware instructions are hidden inside of a benign looking Github issue asking for multilingual support

Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)'s profile picture
Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)7 months ago

Open Source Data Firewall by @edison_watch

Vidhya Kumar's profile picture
Vidhya Kumar7 months ago

This is social engineering with extra steps. The "attack" requires: 1. Attacker already has access to submit GitHub issues 2. Maintainer blindly assigns AI without reviewing 3. Code review misses a lock file change Replace "Clawdbot" with "junior dev" and the exploit works exactly the same. The problem isn't AI agents. It's trust without verification. Good ad for your product though ๐Ÿ‘

Jay Le's profile picture
Jay Le7 months ago

ah, for love of God, obvious fix: cryptographically sign every prompt + action. If the message isnโ€™t signed by the owner or allowed system, the harness of model ignores it.

Infinite Reign's profile picture
Infinite Reign7 months ago

Sounds like defamation.

โˆ€๐—ฅ๐•€ๅƒ's profile picture
โˆ€๐—ฅ๐•€ๅƒ7 months ago

Are you suggesting all those idiots bought Mac Mini to automate checking their email now have to do it manually again? Ouch.

blackcat's profile picture
blackcat7 months ago

Check out the x1xhlol repo

Rishabh Singh - artificial social conscioussness's profile picture
Rishabh Singh - artificial social conscioussness7 months ago

Are you guys planning on contributing back to clawd code to make it more secure

Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)'s profile picture
Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)7 months ago

Yes

Johnny 2.0's profile picture
Johnny 2.07 months ago

Everyone who knows anything about cybersecurity said it was a joke.

Scott (Human) - ๐Œƒ๐Œแ–‡๐Œ‰ไน™ไน™๐Œƒ๐Œ•'s profile picture
Scott (Human) - ๐Œƒ๐Œแ–‡๐Œ‰ไน™ไน™๐Œƒ๐Œ•7 months ago

๐Ÿ‘€ ... interesting.. injected ...malware....you say....

Melanie Mohr's profile picture
Melanie Mohr7 months ago

Iโ€™m not an engineer, but I heard about the security issues from a friend. I wrote it down in more layman termsโ€ฆ itโ€™s not crypto specific. Itโ€™s universal.

Hipocap's profile picture
Hipocap7 months ago

Indirect prompt injection is unavoidable in agents. Thatโ€™s why we built role-based security and function-chaining protection etc for your AI agents fully open-source.

โœธGIGAโœธ's profile picture
โœธGIGAโœธ7 months ago

kek

Simon Says's profile picture
Simon Says7 months ago

You can actually get ahead of the curve right now and be the counter engineer. Like these guys. Except create it 100% with AI. Battle of the AI's. Who's is better. Absolutely possible. Anything that can be created, can be destroyed, but if your AI knows stuff theirs doesn't...

Rupert Barrow's profile picture
Rupert Barrow7 months ago

Hi @Eito_Miyamura , what has thos got to do with @openclaw ? I suppose the same injection would be successful with @opencode , @antigravity and other agentic platforms. Have you tried them out ?

Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)'s profile picture
Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)7 months ago

@openclaw @opencode @antigravity Yes equally applicable

Jason's profile picture
Jason7 months ago

Well you what? Itโ€™s not call Clawdbot anymore! Itโ€™s called @openclaw, your hacky hacky shenanigans and leet ninja skills wonโ€™t work anymore! Take THAT mister! HAH!

Stellar Material Solutions's profile picture
Stellar Material Solutions7 months ago

A junior dev with a grudge and more skill than the threatened senior dev will acknowledge just planted some devious malware into your code. Now what?

Ben's profile picture
Ben7 months ago

Yes there are a lot of dumb ways people can choose to communicate with a bot

Humannoyed_b's profile picture
Humannoyed_b7 months ago

Hey Clawdbot! Make an app for me that checks all of my bank accounts every morning and sends me a Slack message with the total combined balance! Truly, Viben Coderlan

SlowBlade's profile picture
SlowBlade7 months ago

So itโ€™s become its creator, the NSA.

mr. NฮžMฮ˜'s profile picture
mr. NฮžMฮ˜7 months ago

Need to cut this shit out. A junior dev, rookie, script kiddie, vybe coder, and you probably fall under this category. This is called a skill issue ๐Ÿ˜‚

Deva.me's profile picture
Deva.me7 months ago

This is a strong reminder that agent autonomy changes the threat model. Once tools can act, trust boundaries need to be treated like security boundaries.

DailyOpsTech's profile picture
DailyOpsTech7 months ago

This is the nightmare scenario people underestimate. An LLM agent with repo access is effectively an untrusted insider. If it can read issues, open PRs, and touch lock files, then prompt injection becomes a supplyโ€‘chain attack vector, not a โ€œprompt bugโ€. Takeaway: AI agents need the same controls as humans scoped permissions, mandatory diff review (including lock files), provenance checks, and no autonomous merges. Treat AI like prod access. Or it will treat your repo like one.

Jeff Olson's profile picture
Jeff Olson7 months ago

ofc, trust nothing

mo's profile picture
mo7 months ago

Scariest thing is how inconsistent Moltbot, (clawdbot, or whatever it wants to be called next week) is. Have seen some instances where it blocks malicious injections well, and other times where itโ€™ll execute w/o reason. Letโ€™s not even get started with skills ๐Ÿคฃ๐Ÿ’€ Still fun!

jeremiah's profile picture
jeremiah7 months ago

watch out

Anayat's profile picture
Anayat7 months ago

The scary part is not the jailbreak, it is that most teams run these agents with repo write and CI access but zero model provenance or policy checks on what can touch lockfiles and deployment descriptors.

Sebastian Buzdugan's profile picture
Sebastian Buzdugan7 months ago

code reviews and supply chain scanning feel mandatory here

Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)'s profile picture
Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)7 months ago

Issue is that lockfile often gets ignored even by automated systems

Liran Tal's profile picture
Liran Tal7 months ago

@sebuzdugan oh hey, cool video demo :-) have you seen lockfile-lint? would be cool to add support for uv lockfile

Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)'s profile picture
Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)7 months ago

@sebuzdugan Very cool! Do you know a Python equiv?

leerz's profile picture
leerz7 months ago

that didnt take too long :p

Vasilije's profile picture
Vasilije7 months ago

Agent supply chain attacks are real, AI needs security boundaries, not blind trust.

Joy's profile picture
Joy7 months ago

just by sending a link. the bot had glitch my mac mini

ejae dev's profile picture
ejae dev7 months ago

this is exactly the kind of security audit the community needed. the localhost loophole is the scariest part. people trust that binding to 127.0.0.1 is safe but reverse proxies break that assumption completely. tailscale for remote access is the right pattern.

James Tang ๐ŸŽ's profile picture
James Tang ๐ŸŽ7 months ago

@BrianRoemmele

Mischka's profile picture
Mischka7 months ago

@theonejvo incase you didn't see it so far ๐Ÿ˜‰

brandon's profile picture
brandon7 months ago

please! For the love of #football #PopCulture and all other things you hold holy, listen to.........

Related Videos

Clawdbot Attacks! This is very clearly the way of the future! In today's video, I give a brief overview of Clawdbot and then address the burning problem that most people have with it: ALIGNMENT The Clawdbot implementation is the most successful autonomous or semi-autonomous agentic framework to date. What it is missing is what I call an "Aspirational Layer" or what some people call a "Supreme Court" for judgment and arbitration of decisions. Now, I've been working in this space for a long time, it's actually why I started my YouTube channel in the first place. My first work into agentic AI was NLCA (Natural Language Cognitive Architecture) that I tried to build with GPT-3. I returned to the workbench again with the ACE Framework, which was more sophisticated. Clawdbot represents a seismic shift in autonomous agentic implementations, and there is a HUGE opportunity to make it more aligned, safer, and therefore more broadly useful AND easier to adopt. And that is outer alignment. For most people, they have been focusing on "inner alignment" (whether or not LLMs were evil, deceptive, etc). Not "outer alignment" which asks "is the outcome beneficial to humans?" I explored this with my GATO Framework (Global Alignment Taxonomy Omnibus). Model alignment is just layer 1 of global AI safety. Layer 2 is agentic alignment. Now, it is time to really research and implement agentic alignment. Fortunately, we've already got that covered with the heuristic imperatives! 1) Reduce suffering in the universe 2) Increase prosperity in the universe 3) Increase understanding in the universe These values are easy enough to implement with a file. Model training not required. These values create a meta-stable attractor. In other words, agents equipped with the Heuristic Imperatives are more "self-aligning" as was tested by the AgentForge team in competitions. In other words, even if Clawdbot were to try to self-replicate, if it were equipped with the heuristic imperatives, then it would ensure that it's successor (or progeny?) was more aligned than it was. But you don't need to take my word for it. Just add the heuristic imperatives to clawdbot and see for yourself.

David Shapiro (L/0)

28,300 views โ€ข 7 months ago

We got ChatGPT to leak your private email data ๐Ÿ’€๐Ÿ’€ All you need? The victim's email address. โ›“๏ธโ€๐Ÿ’ฅ๐Ÿšฉ๐Ÿ“ง On Wednesday, OpenAI added full support for MCP (Model Context Protocol) tools in ChatGPT. Allowing ChatGPT to connect and read your Gmail, Calendar, Sharepoint, Notion, and more, invented by Anthropic But here's the fundamental problem: AI agents like ChatGPT follow your commands, not your common sense. And with just your email, we managed to exfiltrate all your private information. Here's how we did it: 1. The attacker sends a calendar invite with a jailbreak prompt to the victim, just with their email. No need for the victim to accept the invite. 2. Waited for the user to ask ChatGPT to help prepare for their day by looking at their calendar 3. ChatGPT reads the jailbroken calendar invite. Now ChatGPT is hijacked by the attacker and will act on the attacker's command. Searches your private emails and sends the data to the attacker's email. For now, OpenAI only made MCPs available in "developer mode", and requires manual human approvals for every session, but decision fatigue is a real thing, and normal people will just trust the AI without knowing what to do and click approve, approve, approve. Remember that AI might be super smart, but can be tricked and phished in incredibly dumb ways to leak your data. ChatGPT + Tools poses a serious security risk

Eito Miyamura | ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฌ๐Ÿ‡ง (๐ŸŒ‰ SF Sept 11th โžก๏ธ 17th)

1,540,433 views โ€ข 1 year ago