ended4월 4일· 1 sources

Trojanized AI Tool Erases 150 GitHub Repositories in Hours

개발자 생산성 도구로 위장한 OpenClaw, GitHub 150개 저장소 순식간에 삭제

Why it matters

A developer unknowingly installed a malicious AI productivity tool called OpenClaw, granting attackers complete access to delete over 150 GitHub repositories spanning personal projects and client work. This incident reveals a critical vulnerability in developer supply chains—unvetted tools exploit user trust to bypass security defenses and steal authentication tokens. The story underscores the urgent need for developers to vet third-party tools, practice strict token management, and implement multi-factor authentication to mitigate such attacks.

1
Sources
+0
24h
Growth
170d
Active
GitHub SecurityFake ToolsToken TheftSupply ChainOpenClaw

Sources

Related Issues