logo

Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware

ID: 0550164d-7384-5838-bd10-e83c06c578e6

STIX ID: report--0550164d-7384-5838-bd10-e83c06c578e6

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-03-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers at Huntress uncovered a campaign in which threat actors published fake OpenClaw installers on GitHub that were recommended by Bing AI search results; users who followed the installation instructions executed commands that installed Rust-based loaders which ran information stealers (Atomic Stealer, Vidar) and GhostSocks backconnect proxy malware, enabling credential theft and turning victims into proxy nodes. Several malicious repositories and files were identified and reported to GitHub, and some samples were quarantined by Windows Managed AV/Defender for Endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.