logo

Latest OpenClaw Security Risk: Fake GitHub Repositories Used to Deploy Infostealers

ID: 4c2a1860-a006-5d6b-aa7c-66e583dcf662

STIX ID: report--4c2a1860-a006-5d6b-aa7c-66e583dcf662

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Huntress researchers uncovered a GitHub-based campaign (Feb 2–10) using fraudulent OpenClaw installers (e.g., openclaw-installer, OpenClaw_x64.exe) to deploy infostealers via a 'Steal Packer', a TLS-enabled GhostSocks proxy for routing attacker traffic through victims, and an Atomic macOS Stealer (AMOS); the operation leveraged trusted hosting and search recommendations to increase impact and used in-memory Rust loaders, anti-VM checks, firewall/task persistence, and other evasion techniques before GitHub removed the repositories after reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.