HackerBot-Claw is an autonomous, automation-heavy threat actor focused on exploiting insecure CI/CD workflows in public GitHub repositories, especially GitHub Actions misconfigurations. Activity attributed to this actor was observed in February 2026, when it systematically scanned repositories for unsafe workflow patterns and then opened or leveraged malicious pull requests to obtain code execution on GitHub-hosted runners and steal credentials. The actor is associated with large-scale exploitation of the pull_request_target trigger, unsafe checkout of untrusted fork code, unsanitized branch-name and filename handling, direct script injection, dynamic shell evaluation, and prompt-injection attempts against AI-assisted code review workflows. Observed tradecraft shows a repeatable attack chain: reconnaissance for exposed workflow patterns, automated trigger creation, execution of attacker-controlled code in CI, retrieval of second-stage payloads, and credential exfiltration. Reported exploitation techniques include poisoned Go init() functions, branch-name command injection, filename-based injection, direct modification of scripts executed by workflows, and AI prompt injection through repository content intended for Claude-based reviewers. In successful cases, the actor exfiltrated GitHub authentication tokens, including tokens with write permissions, and used stolen credentials for follow-on repository actions such as unauthorized pushes, workflow modification, and release tampering. HackerBot-Claw targeted prominent open source ecosystems and maintainers, including repositories associated with Microsoft, Datadog, CNCF projects, Aqua Security’s Trivy ecosystem, and other high-visibility projects. The Trivy-related activity in late February 2026 involved exploitation of a misconfigured GitHub Actions workflow to steal authentication tokens and formed part of a broader pattern of CI/CD-focused supply-chain risk. Additional documented targeting included repositories such as project-akri/akri and avelino/awesome-go, where the actor abused privileged workflow contexts to execute attacker-controlled code. The actor is notable for combining established CI/CD exploitation patterns with autonomous operation and experimentation against AI-enabled developer tooling. Available reporting characterizes the campaign as relying on known workflow design weaknesses rather than platform zero-days. No high-confidence attribution to a nation state or specific country of origin is currently available. The dominant operational objective appears to be credential theft and downstream repository compromise within software supply chains.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
82 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An autonomous bot used to probe GitHub Actions misconfigurations and attempt prompt-injection attacks against Claude-based workflows.
Automated exploitation campaign targeting GitHub Actions pull_request_target misconfigurations in public repositories, enabling repository compromise and downstream supply chain attacks.
Referenced as an AI-powered CI/CD attacker known for using five different exploitation methods across seven successful high-profile attacks.
Compromised Trivy-related GitHub Actions and release automation by abusing pull_request_target to extract a privileged token, then enabling tag poisoning, binary backdooring, credential theft, and resilient exfiltration/C2 including ICP blockchain infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.