ended4월 4일· 1 sources
Trojanized AI Tool Erases 150 GitHub Repositories in Hours
개발자 생산성 도구로 위장한 OpenClaw, GitHub 150개 저장소 순식간에 삭제
Why it matters
A developer unknowingly installed a malicious AI productivity tool called OpenClaw, granting attackers complete access to delete over 150 GitHub repositories spanning personal projects and client work. This incident reveals a critical vulnerability in developer supply chains—unvetted tools exploit user trust to bypass security defenses and steal authentication tokens. The story underscores the urgent need for developers to vet third-party tools, practice strict token management, and implement multi-factor authentication to mitigate such attacks.
1
Sources
+0
24h
—
Growth
170d
Active
GitHub SecurityFake ToolsToken TheftSupply ChainOpenClaw