Hackers steal OpenClaw configuration in emerging AI agent threat

Hackers steal OpenClaw configuration in emerging AI agent threat

Hackers steal OpenClaw configuration in emerging AI agent threat

https://securityaffairs.com/188097/malware/hackers-steal-openclaw-configuration-in-emerging-ai-agent-threat.html

Publish Date: 2026-02-17 05:13:00

Source Domain: securityaffairs.com

Hackers steal OpenClaw configuration in emerging AI agent threat

Pierluigi Paganini
February 17, 2026

Researchers found an infostealer stole a victim’s OpenClaw configuration, marking a shift toward targeting personal AI agents.

Cybersecurity researchers have uncovered a new information stealer that exfiltrated a victim’s OpenClaw configuration environment, previously known as Clawdbot and Moltbot. According to cybersecurity firm Hudson Rock, the case highlights a new shift in infostealer activity, moving beyond stealing browser passwords to targeting the identities, settings, and “digital souls” of personal AI agents.

“Following our initial research into ClawdBot, Hudson Rock has now detected a live infection where an infostealer successfully exfiltrated a victim’s OpenClaw configuration environment.” reads the report published by Hudson Rock. “This finding marks a significant milestone in the evolution of infostealer behavior: the transition from stealing browser credentials to harvesting the “souls” and identities of personal AI agents.”

OpenClaw is an open-source personal AI assistant platform that lets users extend its capabilities by installing community-created “skills.” Formerly known as MoltBot and ClawdBot, it integrates with tools like Claude Code and often runs locally or via messaging apps, allowing skills to automate tasks, but also creating security risks if malicious skills are installed.

The researchers described the incident as a “grab-bag” attack: the infostealer did not use a dedicated OpenClaw module but a broad file-harvesting routine that scooped up sensitive extensions and folders, unintentionally capturing the full operational environment of the victim’s OpenClaw AI agent. Stolen files included openclaw.json with gateway tokens, device.json containing private cryptographic keys, and “soul” and memory files outlining the…

Source