
Researchers have discovered that Microsoft Bing’s AI-powered search was recommending a malicious GitHub repository for OpenClaw, a popular open-source AI agent. This allowed threat actors to distribute info-stealing malware to users seeking legitimate installation files.
How the Attack Worked
openclaw-installer and hosted fake repositories that mimicked the real tool’s documentation and code.OpenClaw_x64.exe) that deployed various info-stealers and proxy malware, such as Atomic Stealer (AMOS) and GhostSocks.Target: Sensitive Data
The malware specifically targeted OpenClaw’s configuration files, which contained highly sensitive data:
openclaw.json: Contained gateway authentication tokens for remote access.device.json: Contained private cryptographic keys used for signing and device pairing.soul.md & memory files: Stored the agent’s behavioral logic and personal logs (emails, calendar events, private messages).#bing #fake #hiding #info-stealing #malware #news #openclaw #recommends #repo — News
© Bulletproof Servers. All rights reserved.