Hackerbot-Claw: AI Bot Exploiting GitHub Actions – Microsoft, Datadog Hit So Far

varunsharma07 12 points 3 comments March 01, 2026
www.stepsecurity.io · View on Hacker News

Discussion Highlights (2 comments)

varunsharma07

We analyzed an autonomous bot (hackerbot-claw) that's actively scanning GitHub repos for exploitable Actions workflows. It hit Microsoft, DataDog, a CNCF project, and awesome-go (140k stars) achieving RCE in 4 out of 5 targets and exfiltrating a GITHUB_TOKEN. Full breakdown of the 5 attack techniques with evidence.

aperi

safe to say the root cause is bad PRs (untrusted)?

Semantic search powered by Rivestack pgvector
3,471 stories · 32,344 chunks indexed