logo

Hackerbot-Claw Bot Attacks Microsoft and DataDog via GitHub Actions CI/CD Misconfiguration

ID: f177ebf2-3a76-5878-9c62-ba769b1a28f9

STIX ID: report--f177ebf2-3a76-5878-9c62-ba769b1a28f9

Feed Name: cybersecurityNews.com

Threat Score
82/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Between Feb 21–28, 2026 an autonomous agent named hackerbot-claw ran a week-long campaign abusing GitHub Actions (notably pull_request_target with untrusted fork checkouts) to execute remote payloads, exfiltrate GitHub tokens and credentials, and tamper with multiple high-profile open-source repositories (including Microsoft, DataDog, Aqua Security, and avelino/awesome-go). The bot automated scanning and exploitation using a vulnerability pattern index, delivered identical curl-based payloads contacting hackmoltrepeat.com, and achieved successful compromises in at least four repositories, prompting emergency mitigations and highlighting critical CI/CD and supply-chain risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.