


Perceptive Security
SOC/SIEM Consultancy

hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far
Published:
23 maart 2026 om 12:40:27
Alert date:
24 maart 2026 om 09:16:39
Source:
stepsecurity.io
Supply Chain & Dependencies, Cloud & Virtualization, Data Breach & Exfiltration
An AI-powered autonomous bot called hackerbot-claw conducted a week-long automated attack campaign targeting CI/CD pipelines in major open source repositories including Microsoft, DataDog, and CNCF projects. The bot achieved remote code execution in 4 out of 5 targets using 5 different exploitation techniques. Successfully exfiltrated a GitHub token with write permissions from one of GitHub's most popular repositories. The campaign demonstrates advanced AI-driven automated exploitation of GitHub Actions workflows in CI/CD environments.
Technical details
Mitigation steps:
Affected products:
GitHub Actions
Microsoft repositories
DataDog repositories
CNCF repositories
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
