AI Security · Web App Attack
OpenClaw patched 'ClawJacked', a flaw that let websites connect to local OpenClaw gateways and seize control of AI agents.
5 sources · Mar 6
BleepingComputer
Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware
Fake OpenClaw installers hosted in GitHub repositories and promoted by Microsoft Bing's AI-enhanced search feature instructed users to run commands that deployed information stealers and proxy malware.
originalDark Reading
Critical OpenClaw Vulnerability Exposes AI Agent Risks
The now-patched flaw is the latest in a growing string of security issues with the viral AI tool, which has seen rapid adoption among developers.
originalSecurityWeek
OpenClaw Vulnerability Allowed Websites to Hijack AI Agents
Malicious websites could open a WebSocket connection to localhost on the OpenClaw gateway port, brute force passwords, and take control of the agent.
originalPart of the PlainSec briefing for 2026-03-03
Every edition of this story: OpenClaw Flaw Enabled Hijack of Local AI Agents