216.73.216.226

An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far

· Published 03/03/2026 15:48 · Modified 03/03/2026 16:44

Export JSON

Essential information

Published
03/03/2026 15:48
Modified
03/03/2026 16:44
Tags
2026-03-03 autonomous bot ci/cd github actions open-source remote code execution supply chain attack token theft
Related entities
4 observables, 1 intrusion sets (apt), 8 techniques (mitre), 2 others

Description

A week-long automated attack campaign targeted pipelines across major open source repositories, achieving in multiple targets. The attacker, an called hackerbot-claw, used five different exploitation techniques and successfully exfiltrated a GitHub token with write permissions from one of the most popular repositories on GitHub. The campaign targeted repositories belonging to Microsoft, DataDog, CNCF, and other popular open source projects. The attacks included via poisoned Go scripts, direct script injection, branch name injection, filename injection, and AI prompt injection. The most severe attack resulted in a full repository compromise of Aqua Security's Trivy project. The campaign highlights the growing threat of AI-powered bots targeting software supply chains and the need for automated security controls in pipelines.

External references