Viral Moltbot AI assistant raises concerns over data security
ID: 895c5701-4939-5160-b539-9ef9e9e21177
STIX ID: report--895c5701-4939-5160-b539-9ef9e9e21177
Feed Name: Bleeping Computer
Security researchers warn that insecure deployments of the Moltbot (Clawdbot) local AI assistant have left admin interfaces exposed and misconfigured (reverse proxies treating external traffic as local), enabling credential theft, API/OAuth token leakage, conversation-history access, and potential remote/root command execution. A researcher demonstrated a supply‑chain attack by promoting a malicious Skill on the official registry, and additional reports describe malicious VSCode extensions and the likelihood that info‑stealer malware will target Moltbot's local storage; recommended mitigations include isolating instances in VMs and applying strict network/firewall rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
