logo

Security Alert: “Hackerbot-Claw” Autonomous Campaign Exploits GitHub Actions

ID: 07d03fd3-ea7b-5af8-8a7e-5fa6d03dcc2c

STIX ID: report--07d03fd3-ea7b-5af8-8a7e-5fa6d03dcc2c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-03

Date Updated: 2026-04-23

Author: Ddos

...
...

Hackerbot-claw is an active, automated campaign that systematically exploits misconfigured GitHub Actions workflows in public repositories to inject code, exfiltrate GITHUB_TOKEN credentials, and enable unauthorized pushes or supply-chain compromise; the report details exploitation techniques, cites real compromises (e.g., project-akri/akri), and recommends hardening CI/CD workflows, least-privilege tokens, authorization checks, code review protections, and pinning third-party actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.