logo

Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens

ID: 8661ecd8-e1a9-5d68-8018-ce35cd388717

STIX ID: report--8661ecd8-e1a9-5d68-8018-ce35cd388717

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-02-16

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers observed an information-stealer (attributed as a likely Vidar variant) exfiltrating OpenClaw agent configuration files — including openclaw.json (gateway token), device.json (cryptographic keys), and soul.md (agent operational data) — via a generic file-grabbing routine. The theft enables impersonation of AI agents and remote access if ports are exposed; security firms also report hundreds of thousands of exposed OpenClaw instances with potential RCE risk, and malicious ClawHub skills campaigns that host payloads externally to evade VirusTotal scanning, raising supply-chain and operational-security concerns for agentic AI deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.