Bing AI Recommends Fake OpenClaw Repo Hiding Info-Stealing Malware
Mar 6, 2026 // 01:52 - Tristan Wall


Researchers have discovered that Microsoft Bing’s AI-powered search was recommending a malicious GitHub repository for OpenClaw, a popular open-source AI agent. This allowed threat actors to distribute info-stealing malware to users seeking legitimate installation files.

How the Attack Worked

  • Trust Exploitation: Attackers created a GitHub organization called openclaw-installer and hosted fake repositories that mimicked the real tool’s documentation and code.
  • AI Recommendation Poisoning: By optimizing these fake repositories with AI-generated README files and keywords, the attackers “poisoned” Bing’s index. This led Bing’s AI assistant to suggest the malicious link as the primary download source for “OpenClaw Windows.”
  • Payload Delivery: Users who followed the AI’s suggestion downloaded an executable (OpenClaw_x64.exe) that deployed various info-stealers and proxy malware, such as Atomic Stealer (AMOS) and GhostSocks.

Target: Sensitive Data

The malware specifically targeted OpenClaw’s configuration files, which contained highly sensitive data:

  • openclaw.json: Contained gateway authentication tokens for remote access.
  • device.json: Contained private cryptographic keys used for signing and device pairing.
  • soul.md & memory files: Stored the agent’s behavioral logic and personal logs (emails, calendar events, private messages).

#bing  #fake  #hiding  #info-stealing  #malware  #news  #openclaw  #recommends  #repo   —   News