Latest OpenClaw Security Risk: Fake GitHub Repositories Used to Deploy Infostealers
ID: 4c2a1860-a006-5d6b-aa7c-66e583dcf662
STIX ID: report--4c2a1860-a006-5d6b-aa7c-66e583dcf662
Feed Name: Security Boulevard
Huntress researchers uncovered a GitHub-based campaign (Feb 2–10) using fraudulent OpenClaw installers (e.g., openclaw-installer, OpenClaw_x64.exe) to deploy infostealers via a 'Steal Packer', a TLS-enabled GhostSocks proxy for routing attacker traffic through victims, and an Atomic macOS Stealer (AMOS); the operation leveraged trusted hosting and search recommendations to increase impact and used in-memory Rust loaders, anti-VM checks, firewall/task persistence, and other evasion techniques before GitHub removed the repositories after reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
