


Perceptive Security
SOC/SIEM Consultancy

hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far
Published:
2 March 2026 at 01:56:16
Alert date:
2 March 2026 at 02:01:00
Source:
stepsecurity.io
Supply Chain & Dependencies, Cloud & Virtualization
An AI-powered autonomous bot called hackerbot-claw conducted a week-long automated attack campaign targeting CI/CD pipelines across major open source repositories. The bot successfully achieved remote code execution in at least 4 out of 5 targets using 5 different exploitation techniques. The campaign hit major projects including Microsoft, DataDog, and CNCF repositories. The attacker successfully exfiltrated a GitHub token with write permissions from one of the most popular repositories on GitHub. This represents an active exploitation of GitHub Actions workflows with demonstrated success against high-profile targets.
Technical details
Mitigation steps:
Affected products:
GitHub Actions
GitHub
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
