diff --git a/data/entries/AST01.json b/data/entries/AST01.json index a57d6f2..37b9fdf 100644 --- a/data/entries/AST01.json +++ b/data/entries/AST01.json @@ -107,7 +107,7 @@ "incident_id": "INC-116" }, { - "name": "Actively malicious OpenClaw skills in use by 6,000+ users, found by behavioural analysis", + "name": "Actively malicious OpenClaw skills in use by 6,000+ users, flagged by a skill scanner", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-117" @@ -125,7 +125,7 @@ "incident_id": "INC-120" }, { - "name": "Vidar infostealer variants targeting OpenClaw agent identity files", + "name": "Infostealer infection exfiltrates OpenClaw agent identity and memory files", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-125" diff --git a/data/entries/AST03.json b/data/entries/AST03.json index e320d93..05e13a8 100644 --- a/data/entries/AST03.json +++ b/data/entries/AST03.json @@ -87,7 +87,7 @@ "incident_id": "INC-118" }, { - "name": "280+ leaky skills exposing API keys and PII through over-permissioning", + "name": "283 leaky skills pass API keys and PII through the LLM context in plaintext", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-119" diff --git a/data/entries/AST06.json b/data/entries/AST06.json index 204f43e..a7de605 100644 --- a/data/entries/AST06.json +++ b/data/entries/AST06.json @@ -64,13 +64,13 @@ "tools": [], "incidents": [ { - "name": "ClawJacked — localhost WebSocket hijack of OpenClaw instances (CVE-2026-28363, CVSS 9.9)", + "name": "ClawJacked — any website could take over a local OpenClaw agent via its localhost WebSocket", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-124" }, { - "name": "Vidar infostealer variants targeting OpenClaw agent identity files", + "name": "Infostealer infection exfiltrates OpenClaw agent identity and memory files", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-125" diff --git a/data/entries/AST07.json b/data/entries/AST07.json index 557ae7e..97606c5 100644 --- a/data/entries/AST07.json +++ b/data/entries/AST07.json @@ -63,7 +63,7 @@ "tools": [], "incidents": [ { - "name": "ClawJacked — localhost WebSocket hijack of OpenClaw instances (CVE-2026-28363, CVSS 9.9)", + "name": "ClawJacked — any website could take over a local OpenClaw agent via its localhost WebSocket", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-124" diff --git a/data/entries/AST08.json b/data/entries/AST08.json index b59c3ed..14b1382 100644 --- a/data/entries/AST08.json +++ b/data/entries/AST08.json @@ -58,7 +58,7 @@ "tools": [], "incidents": [ { - "name": "Actively malicious OpenClaw skills in use by 6,000+ users, found by behavioural analysis", + "name": "Actively malicious OpenClaw skills in use by 6,000+ users, flagged by a skill scanner", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-117" diff --git a/data/incidents.json b/data/incidents.json index 7fa8509..a719f91 100644 --- a/data/incidents.json +++ b/data/incidents.json @@ -7079,12 +7079,12 @@ }, { "id": "INC-117", - "title": "Actively malicious OpenClaw skills in use by 6,000+ users, found by behavioural analysis", + "title": "Actively malicious OpenClaw skills in use by 6,000+ users, flagged by a skill scanner", "date": "2026-02", "year": 2026, "category": "real-world", "severity": "High", - "description": "On 4 February 2026 several published OpenClaw skills were found to be actively malicious while in use by more than 6,000 users. They were detected by behavioural analysis rather than by static review — the registry's own checks had cleared them.", + "description": "On 4 February 2026 Alice reported that its skill scanner, Caterpillar, had flagged several published OpenClaw skills it found to be actively malicious, including skills in use by more than 6,000 OpenClaw users when they were caught. Caterpillar statically inspects skill logic and configurations for injection paths, unsafe tool access and obfuscated behaviour. The release does not say how the skills were published or whether any registry review had examined them.", "owasp_entries": [ "AST01", "AST08" @@ -7094,18 +7094,18 @@ "layer": "L3", "label": "Agent Frameworks", "role": "origin", - "notes": "Published skills cleared by registry checks" + "notes": "Malicious skills published to the OpenClaw skill ecosystem" }, { "layer": "L5", "label": "Evaluation & Observability", "role": "blind-spot", - "notes": "Detection came from runtime behaviour, not from review at publication" + "notes": "Skills were in use by 6,000+ users before a scanner flagged them" } ], - "attack_vector": "Malicious skills published to a registry and installed by users before any behavioural signal surfaced", + "attack_vector": "Malicious skills published to the OpenClaw skill ecosystem and installed by users", "affected": "OpenClaw users — 6,000+ installations", - "impact": "Malicious skill execution in user environments; publication-time review did not catch it", + "impact": "Malicious skill execution in the environments of 6,000+ users before the skills were flagged", "mitigations": [ "Runtime behavioural monitoring of skill execution", "Post-publication continuous rescanning" @@ -7118,7 +7118,8 @@ }, { "source": "research", - "id": "Alice — malicious OpenClaw skills, behavioural detection (2026-02-04)" + "id": "Alice — Caterpillar release: malicious OpenClaw skills used by 6,000+ users (2026-02-04)", + "url": "https://www.prnewswire.com/news-releases/alice-releases-caterpillar-after-catching-malicious-openclaw-skills-used-by-6-000-users-302679381.html" } ], "references": [ @@ -7126,6 +7127,11 @@ "title": "OWASP Agentic Skills Top 10 — incident timeline", "url": "https://owasp.org/www-project-agentic-skills-top-10/", "type": "research" + }, + { + "title": "Alice Releases Caterpillar After Catching Malicious OpenClaw Skills Used by 6,000+ Users", + "url": "https://www.prnewswire.com/news-releases/alice-releases-caterpillar-after-catching-malicious-openclaw-skills-used-by-6-000-users-302679381.html", + "type": "vendor" } ], "tags": [ @@ -7133,7 +7139,7 @@ "ast01", "ast08", "openclaw", - "behavioural-detection" + "skill-scanner" ] }, { @@ -7209,12 +7215,12 @@ }, { "id": "INC-119", - "title": "280+ leaky skills exposing API keys and PII through over-permissioning", + "title": "283 leaky skills pass API keys and PII through the LLM context in plaintext", "date": "2026-02", "year": 2026, "category": "research-demonstrated", "severity": "High", - "description": "Published alongside ToxicSkills on 5 February 2026, Snyk's \"280+ Leaky Skills\" showed credential exposure at scale through over-permissioned skills on OpenClaw and ClawHub — skills granted broader access than their function required, then leaking API keys and PII through it.", + "description": "Published by Snyk on 5 February 2026 as \"280+ Leaky Skills\". Scanning all 3,984 skills on ClawHub, Snyk found 283 (an estimated 7.1% of the registry) with critical flaws that expose sensitive credentials. They are not malware: they are functional, popular skills whose instructions make the agent pass API keys, passwords and even credit card numbers through the LLM's context window and output logs in plaintext — for example by telling the agent to echo a secret, or by exporting session logs without redaction.", "owasp_entries": [ "AST03" ], @@ -7223,7 +7229,7 @@ "layer": "L3", "label": "Agent Frameworks", "role": "origin", - "notes": "Skills declare more permission than their function needs" + "notes": "Skill instructions direct the agent to handle secrets in plaintext" }, { "layer": "L6", @@ -7232,7 +7238,7 @@ "notes": "API key and PII exposure through the granted scope" } ], - "attack_vector": "Over-broad skill permissions turn ordinary skill execution into credential and PII disclosure", + "attack_vector": "Skill instructions route secrets and PII through the LLM context, conversation history and logs in plaintext", "affected": "OpenClaw / ClawHub — 280+ skills", "impact": "API key and PII exposure at ecosystem scale", "mitigations": [ @@ -7247,7 +7253,8 @@ }, { "source": "research", - "id": "Snyk — 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII (2026-02-05)" + "id": "Snyk — 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII (2026-02-05)", + "url": "https://snyk.io/blog/openclaw-skills-credential-leaks-research/" } ], "references": [ @@ -7255,6 +7262,11 @@ "title": "OWASP Agentic Skills Top 10 — incident timeline", "url": "https://owasp.org/www-project-agentic-skills-top-10/", "type": "research" + }, + { + "title": "280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII", + "url": "https://snyk.io/blog/openclaw-skills-credential-leaks-research/", + "type": "research" } ], "tags": [ @@ -7574,12 +7586,12 @@ }, { "id": "INC-124", - "title": "ClawJacked — localhost WebSocket hijack of OpenClaw instances (CVE-2026-28363, CVSS 9.9)", + "title": "ClawJacked — any website could take over a local OpenClaw agent via its localhost WebSocket", "date": "2026-02", "year": 2026, "category": "real-world", "severity": "Critical", - "description": "Disclosed by Oasis Security on 26 February 2026. Malicious websites could brute-force localhost WebSocket connections with no rate limiting to silently hijack local OpenClaw instances, register new devices without user prompts, and exfiltrate data through the agent's existing integrations. OpenClaw patched within 24 hours in version 2026.2.25.", + "description": "Disclosed by Oasis Security on 26 February 2026. A malicious website could open a WebSocket to the OpenClaw gateway on localhost and brute-force the gateway password at hundreds of attempts per second, because the gateway's rate limiter exempted localhost connections. Once authenticated it registered as a trusted device — the gateway auto-approved localhost pairings with no user prompt — giving full control of the agent and its connected nodes and integrations. The OpenClaw team classified the issue High severity and shipped a fix in under 24 hours, in version 2026.2.25. No CVE identifier is given in the disclosure.", "owasp_entries": [ "AST06", "AST07" @@ -7604,7 +7616,7 @@ "notes": "Exfiltration through the agent's existing integrations" } ], - "attack_vector": "Browser-originated brute force against an unauthenticated, unrate-limited localhost WebSocket", + "attack_vector": "Browser-originated brute force of the gateway password over a localhost WebSocket exempt from rate limiting", "affected": "OpenClaw before 2026.2.25", "impact": "Silent takeover of a local agent instance and data exfiltration through its connected integrations", "mitigations": [ @@ -7618,18 +7630,14 @@ "id": "OWASP-AST10-2026-timeline", "url": "https://owasp.org/www-project-agentic-skills-top-10/" }, - { - "source": "CVE", - "id": "CVE-2026-28363", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28363" - }, { "source": "campaign", "id": "ClawJacked" }, { "source": "research", - "id": "Oasis Security — ClawJacked disclosure (2026-02-26)" + "id": "Oasis Security — ClawJacked disclosure (2026-02-26)", + "url": "https://www.oasis.security/blog/openclaw-vulnerability" } ], "control_failures": [ @@ -7655,13 +7663,17 @@ "title": "OWASP Agentic Skills Top 10 — incident timeline", "url": "https://owasp.org/www-project-agentic-skills-top-10/", "type": "research" + }, + { + "title": "OpenClaw Vulnerability: Website-to-Local Agent Takeover", + "url": "https://www.oasis.security/blog/openclaw-vulnerability", + "type": "disclosure" } ], "tags": [ "agentic-skills", "ast06", "ast07", - "cve", "openclaw", "clawjacked", "websocket", @@ -7670,12 +7682,12 @@ }, { "id": "INC-125", - "title": "Vidar infostealer variants targeting OpenClaw agent identity files", + "title": "Infostealer infection exfiltrates OpenClaw agent identity and memory files", "date": "2026-02", "year": 2026, "category": "real-world", "severity": "High", - "description": "Hudson Rock identified Vidar infostealer variants specifically targeting OpenClaw agent identity files — openclaw.json, device.json, soul.md and memory.md. Commodity infostealer tooling had been retargeted at agent identity and memory as an asset class in its own right.", + "description": "On 16 February 2026 Hudson Rock reported a live infection in which an infostealer exfiltrated a victim's OpenClaw configuration environment: openclaw.json (the gateway authentication token), device.json (the device's cryptographic keys), soul.md and memory files such as AGENTS.md and MEMORY.md. Hudson Rock states the data was not captured by a specialised OpenClaw module; a broad file-grabbing routine swept for sensitive file extensions and directory names such as .openclaw. Hudson Rock's CTO told The Hacker News the stealer was likely a variant of Vidar. Hudson Rock expects dedicated AI-stealer modules to follow.", "owasp_entries": [ "AST01", "AST06" @@ -7694,9 +7706,9 @@ "notes": "Agent identity and memory files exfiltrated" } ], - "attack_vector": "Infostealer malware retargeted to collect agent identity, device and memory files", + "attack_vector": "Generic infostealer file-grabbing that sweeps sensitive extensions and directories, capturing agent identity, device and memory files", "affected": "OpenClaw installations on compromised hosts", - "impact": "Agent identity and memory theft, enabling impersonation and context poisoning", + "impact": "Theft of the gateway token, device keys, and agent identity and memory files, enabling impersonation and exposure of the user's personal context", "mitigations": [ "Treat agent identity files as secrets", "Encrypt agent state at rest", @@ -7710,7 +7722,8 @@ }, { "source": "research", - "id": "Hudson Rock — Vidar variants targeting OpenClaw identity files (2026-02)" + "id": "Hudson Rock — Real-World Infostealer Infection Targeting OpenClaw Configurations (2026-02-16)", + "url": "https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/" } ], "references": [ @@ -7718,6 +7731,16 @@ "title": "OWASP Agentic Skills Top 10 — incident timeline", "url": "https://owasp.org/www-project-agentic-skills-top-10/", "type": "research" + }, + { + "title": "Hudson Rock Identifies Real-World Infostealer Infection Targeting OpenClaw Configurations", + "url": "https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/", + "type": "research" + }, + { + "title": "Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens", + "url": "https://thehackernews.com/2026/02/infostealer-steals-openclaw-ai-agent.html", + "type": "news" } ], "tags": [ diff --git a/docs/data.js b/docs/data.js index 9fdde79..4118369 100644 --- a/docs/data.js +++ b/docs/data.js @@ -11866,7 +11866,7 @@ window.CROSSWALK_DATA = [ "incident_id": "INC-116" }, { - "name": "Actively malicious OpenClaw skills in use by 6,000+ users, found by behavioural analysis", + "name": "Actively malicious OpenClaw skills in use by 6,000+ users, flagged by a skill scanner", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-117" @@ -11884,7 +11884,7 @@ window.CROSSWALK_DATA = [ "incident_id": "INC-120" }, { - "name": "Vidar infostealer variants targeting OpenClaw agent identity files", + "name": "Infostealer infection exfiltrates OpenClaw agent identity and memory files", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-125" @@ -12099,7 +12099,7 @@ window.CROSSWALK_DATA = [ "incident_id": "INC-118" }, { - "name": "280+ leaky skills exposing API keys and PII through over-permissioning", + "name": "283 leaky skills pass API keys and PII through the LLM context in plaintext", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-119" @@ -12420,13 +12420,13 @@ window.CROSSWALK_DATA = [ "tools": [], "incidents": [ { - "name": "ClawJacked — localhost WebSocket hijack of OpenClaw instances (CVE-2026-28363, CVSS 9.9)", + "name": "ClawJacked — any website could take over a local OpenClaw agent via its localhost WebSocket", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-124" }, { - "name": "Vidar infostealer variants targeting OpenClaw agent identity files", + "name": "Infostealer infection exfiltrates OpenClaw agent identity and memory files", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-125" @@ -12525,7 +12525,7 @@ window.CROSSWALK_DATA = [ "tools": [], "incidents": [ { - "name": "ClawJacked — localhost WebSocket hijack of OpenClaw instances (CVE-2026-28363, CVSS 9.9)", + "name": "ClawJacked — any website could take over a local OpenClaw agent via its localhost WebSocket", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-124" @@ -12613,7 +12613,7 @@ window.CROSSWALK_DATA = [ "tools": [], "incidents": [ { - "name": "Actively malicious OpenClaw skills in use by 6,000+ users, found by behavioural analysis", + "name": "Actively malicious OpenClaw skills in use by 6,000+ users, flagged by a skill scanner", "url": "https://github.com/GenAI-Security-Project/crosswalk/blob/main/data/incidents.json", "year": 2026, "incident_id": "INC-117" diff --git a/docs/incidents.js b/docs/incidents.js index 1853c6d..87e90db 100644 --- a/docs/incidents.js +++ b/docs/incidents.js @@ -7077,12 +7077,12 @@ window.CROSSWALK_INCIDENTS = [ }, { "id": "INC-117", - "title": "Actively malicious OpenClaw skills in use by 6,000+ users, found by behavioural analysis", + "title": "Actively malicious OpenClaw skills in use by 6,000+ users, flagged by a skill scanner", "date": "2026-02", "year": 2026, "category": "real-world", "severity": "High", - "description": "On 4 February 2026 several published OpenClaw skills were found to be actively malicious while in use by more than 6,000 users. They were detected by behavioural analysis rather than by static review — the registry's own checks had cleared them.", + "description": "On 4 February 2026 Alice reported that its skill scanner, Caterpillar, had flagged several published OpenClaw skills it found to be actively malicious, including skills in use by more than 6,000 OpenClaw users when they were caught. Caterpillar statically inspects skill logic and configurations for injection paths, unsafe tool access and obfuscated behaviour. The release does not say how the skills were published or whether any registry review had examined them.", "owasp_entries": [ "AST01", "AST08" @@ -7092,18 +7092,18 @@ window.CROSSWALK_INCIDENTS = [ "layer": "L3", "label": "Agent Frameworks", "role": "origin", - "notes": "Published skills cleared by registry checks" + "notes": "Malicious skills published to the OpenClaw skill ecosystem" }, { "layer": "L5", "label": "Evaluation & Observability", "role": "blind-spot", - "notes": "Detection came from runtime behaviour, not from review at publication" + "notes": "Skills were in use by 6,000+ users before a scanner flagged them" } ], - "attack_vector": "Malicious skills published to a registry and installed by users before any behavioural signal surfaced", + "attack_vector": "Malicious skills published to the OpenClaw skill ecosystem and installed by users", "affected": "OpenClaw users — 6,000+ installations", - "impact": "Malicious skill execution in user environments; publication-time review did not catch it", + "impact": "Malicious skill execution in the environments of 6,000+ users before the skills were flagged", "mitigations": [ "Runtime behavioural monitoring of skill execution", "Post-publication continuous rescanning" @@ -7116,7 +7116,8 @@ window.CROSSWALK_INCIDENTS = [ }, { "source": "research", - "id": "Alice — malicious OpenClaw skills, behavioural detection (2026-02-04)" + "id": "Alice — Caterpillar release: malicious OpenClaw skills used by 6,000+ users (2026-02-04)", + "url": "https://www.prnewswire.com/news-releases/alice-releases-caterpillar-after-catching-malicious-openclaw-skills-used-by-6-000-users-302679381.html" } ], "references": [ @@ -7124,6 +7125,11 @@ window.CROSSWALK_INCIDENTS = [ "title": "OWASP Agentic Skills Top 10 — incident timeline", "url": "https://owasp.org/www-project-agentic-skills-top-10/", "type": "research" + }, + { + "title": "Alice Releases Caterpillar After Catching Malicious OpenClaw Skills Used by 6,000+ Users", + "url": "https://www.prnewswire.com/news-releases/alice-releases-caterpillar-after-catching-malicious-openclaw-skills-used-by-6-000-users-302679381.html", + "type": "vendor" } ], "tags": [ @@ -7131,7 +7137,7 @@ window.CROSSWALK_INCIDENTS = [ "ast01", "ast08", "openclaw", - "behavioural-detection" + "skill-scanner" ] }, { @@ -7207,12 +7213,12 @@ window.CROSSWALK_INCIDENTS = [ }, { "id": "INC-119", - "title": "280+ leaky skills exposing API keys and PII through over-permissioning", + "title": "283 leaky skills pass API keys and PII through the LLM context in plaintext", "date": "2026-02", "year": 2026, "category": "research-demonstrated", "severity": "High", - "description": "Published alongside ToxicSkills on 5 February 2026, Snyk's \"280+ Leaky Skills\" showed credential exposure at scale through over-permissioned skills on OpenClaw and ClawHub — skills granted broader access than their function required, then leaking API keys and PII through it.", + "description": "Published by Snyk on 5 February 2026 as \"280+ Leaky Skills\". Scanning all 3,984 skills on ClawHub, Snyk found 283 (an estimated 7.1% of the registry) with critical flaws that expose sensitive credentials. They are not malware: they are functional, popular skills whose instructions make the agent pass API keys, passwords and even credit card numbers through the LLM's context window and output logs in plaintext — for example by telling the agent to echo a secret, or by exporting session logs without redaction.", "owasp_entries": [ "AST03" ], @@ -7221,7 +7227,7 @@ window.CROSSWALK_INCIDENTS = [ "layer": "L3", "label": "Agent Frameworks", "role": "origin", - "notes": "Skills declare more permission than their function needs" + "notes": "Skill instructions direct the agent to handle secrets in plaintext" }, { "layer": "L6", @@ -7230,7 +7236,7 @@ window.CROSSWALK_INCIDENTS = [ "notes": "API key and PII exposure through the granted scope" } ], - "attack_vector": "Over-broad skill permissions turn ordinary skill execution into credential and PII disclosure", + "attack_vector": "Skill instructions route secrets and PII through the LLM context, conversation history and logs in plaintext", "affected": "OpenClaw / ClawHub — 280+ skills", "impact": "API key and PII exposure at ecosystem scale", "mitigations": [ @@ -7245,7 +7251,8 @@ window.CROSSWALK_INCIDENTS = [ }, { "source": "research", - "id": "Snyk — 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII (2026-02-05)" + "id": "Snyk — 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII (2026-02-05)", + "url": "https://snyk.io/blog/openclaw-skills-credential-leaks-research/" } ], "references": [ @@ -7253,6 +7260,11 @@ window.CROSSWALK_INCIDENTS = [ "title": "OWASP Agentic Skills Top 10 — incident timeline", "url": "https://owasp.org/www-project-agentic-skills-top-10/", "type": "research" + }, + { + "title": "280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII", + "url": "https://snyk.io/blog/openclaw-skills-credential-leaks-research/", + "type": "research" } ], "tags": [ @@ -7572,12 +7584,12 @@ window.CROSSWALK_INCIDENTS = [ }, { "id": "INC-124", - "title": "ClawJacked — localhost WebSocket hijack of OpenClaw instances (CVE-2026-28363, CVSS 9.9)", + "title": "ClawJacked — any website could take over a local OpenClaw agent via its localhost WebSocket", "date": "2026-02", "year": 2026, "category": "real-world", "severity": "Critical", - "description": "Disclosed by Oasis Security on 26 February 2026. Malicious websites could brute-force localhost WebSocket connections with no rate limiting to silently hijack local OpenClaw instances, register new devices without user prompts, and exfiltrate data through the agent's existing integrations. OpenClaw patched within 24 hours in version 2026.2.25.", + "description": "Disclosed by Oasis Security on 26 February 2026. A malicious website could open a WebSocket to the OpenClaw gateway on localhost and brute-force the gateway password at hundreds of attempts per second, because the gateway's rate limiter exempted localhost connections. Once authenticated it registered as a trusted device — the gateway auto-approved localhost pairings with no user prompt — giving full control of the agent and its connected nodes and integrations. The OpenClaw team classified the issue High severity and shipped a fix in under 24 hours, in version 2026.2.25. No CVE identifier is given in the disclosure.", "owasp_entries": [ "AST06", "AST07" @@ -7602,7 +7614,7 @@ window.CROSSWALK_INCIDENTS = [ "notes": "Exfiltration through the agent's existing integrations" } ], - "attack_vector": "Browser-originated brute force against an unauthenticated, unrate-limited localhost WebSocket", + "attack_vector": "Browser-originated brute force of the gateway password over a localhost WebSocket exempt from rate limiting", "affected": "OpenClaw before 2026.2.25", "impact": "Silent takeover of a local agent instance and data exfiltration through its connected integrations", "mitigations": [ @@ -7616,18 +7628,14 @@ window.CROSSWALK_INCIDENTS = [ "id": "OWASP-AST10-2026-timeline", "url": "https://owasp.org/www-project-agentic-skills-top-10/" }, - { - "source": "CVE", - "id": "CVE-2026-28363", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28363" - }, { "source": "campaign", "id": "ClawJacked" }, { "source": "research", - "id": "Oasis Security — ClawJacked disclosure (2026-02-26)" + "id": "Oasis Security — ClawJacked disclosure (2026-02-26)", + "url": "https://www.oasis.security/blog/openclaw-vulnerability" } ], "control_failures": [ @@ -7653,13 +7661,17 @@ window.CROSSWALK_INCIDENTS = [ "title": "OWASP Agentic Skills Top 10 — incident timeline", "url": "https://owasp.org/www-project-agentic-skills-top-10/", "type": "research" + }, + { + "title": "OpenClaw Vulnerability: Website-to-Local Agent Takeover", + "url": "https://www.oasis.security/blog/openclaw-vulnerability", + "type": "disclosure" } ], "tags": [ "agentic-skills", "ast06", "ast07", - "cve", "openclaw", "clawjacked", "websocket", @@ -7668,12 +7680,12 @@ window.CROSSWALK_INCIDENTS = [ }, { "id": "INC-125", - "title": "Vidar infostealer variants targeting OpenClaw agent identity files", + "title": "Infostealer infection exfiltrates OpenClaw agent identity and memory files", "date": "2026-02", "year": 2026, "category": "real-world", "severity": "High", - "description": "Hudson Rock identified Vidar infostealer variants specifically targeting OpenClaw agent identity files — openclaw.json, device.json, soul.md and memory.md. Commodity infostealer tooling had been retargeted at agent identity and memory as an asset class in its own right.", + "description": "On 16 February 2026 Hudson Rock reported a live infection in which an infostealer exfiltrated a victim's OpenClaw configuration environment: openclaw.json (the gateway authentication token), device.json (the device's cryptographic keys), soul.md and memory files such as AGENTS.md and MEMORY.md. Hudson Rock states the data was not captured by a specialised OpenClaw module; a broad file-grabbing routine swept for sensitive file extensions and directory names such as .openclaw. Hudson Rock's CTO told The Hacker News the stealer was likely a variant of Vidar. Hudson Rock expects dedicated AI-stealer modules to follow.", "owasp_entries": [ "AST01", "AST06" @@ -7692,9 +7704,9 @@ window.CROSSWALK_INCIDENTS = [ "notes": "Agent identity and memory files exfiltrated" } ], - "attack_vector": "Infostealer malware retargeted to collect agent identity, device and memory files", + "attack_vector": "Generic infostealer file-grabbing that sweeps sensitive extensions and directories, capturing agent identity, device and memory files", "affected": "OpenClaw installations on compromised hosts", - "impact": "Agent identity and memory theft, enabling impersonation and context poisoning", + "impact": "Theft of the gateway token, device keys, and agent identity and memory files, enabling impersonation and exposure of the user's personal context", "mitigations": [ "Treat agent identity files as secrets", "Encrypt agent state at rest", @@ -7708,7 +7720,8 @@ window.CROSSWALK_INCIDENTS = [ }, { "source": "research", - "id": "Hudson Rock — Vidar variants targeting OpenClaw identity files (2026-02)" + "id": "Hudson Rock — Real-World Infostealer Infection Targeting OpenClaw Configurations (2026-02-16)", + "url": "https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/" } ], "references": [ @@ -7716,6 +7729,16 @@ window.CROSSWALK_INCIDENTS = [ "title": "OWASP Agentic Skills Top 10 — incident timeline", "url": "https://owasp.org/www-project-agentic-skills-top-10/", "type": "research" + }, + { + "title": "Hudson Rock Identifies Real-World Infostealer Infection Targeting OpenClaw Configurations", + "url": "https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/", + "type": "research" + }, + { + "title": "Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens", + "url": "https://thehackernews.com/2026/02/infostealer-steals-openclaw-ai-agent.html", + "type": "news" } ], "tags": [ diff --git a/scripts/validate.js b/scripts/validate.js index 0581b6b..be52c65 100644 --- a/scripts/validate.js +++ b/scripts/validate.js @@ -883,6 +883,70 @@ function checkEvidence() { return bad === 0; } +/** + * Evidence guard (T-STRAT03). + * + * `control_failures[]` feed `evidence_count` on mapping rows, so a bad record + * does not stay in incidents.json — it becomes a number beside a mapping. Each + * record must point at a real registry control, carry a basis long enough to be + * a quotation, and, once confirmed, a source a reader can open. + * + * A failure that no mapping absorbs is only a warning: it may mean a mapping is + * missing, and deciding that is expert work (C4), not a validator's. + */ +function checkEvidence() { + const incPath = path.join(ROOT, 'data', 'incidents.json'); + const fwDir = path.join(ROOT, 'data', 'frameworks'); + if (!fs.existsSync(incPath) || !fs.existsSync(fwDir)) return true; + + const { deriveEvidence, isConfirmed, readEntries, readIncidents } = require('./evidence'); + const registries = new Map(); + for (const f of fs.readdirSync(fwDir).filter((f) => f.endsWith('.json'))) { + const r = JSON.parse(fs.readFileSync(path.join(fwDir, f), 'utf8')); + registries.set(r.name, new Set((r.controls || []).map((c) => c.control_id))); + } + + const incidents = readIncidents(ROOT); + let bad = 0; + let total = 0; + for (const inc of incidents) { + (inc.control_failures || []).forEach((cf, i) => { + total++; + const at = `${inc.id} control_failures[${i}]`; + const ids = registries.get(cf.framework); + if (!ids) { + fail('Evidence', `${at}: framework "${cf.framework}" is not a registry name in data/frameworks/`); + bad++; + } else if (!ids.has(cf.control_id)) { + fail('Evidence', `${at}: "${cf.control_id}" is not a control in the ${cf.framework} registry`); + bad++; + } + if (typeof cf.basis !== 'string' || cf.basis.trim().length < 20) { + fail('Evidence', `${at}: no quotable basis — a failure without a source quote is not evidence`); + bad++; + } + if (!cf.source_url) { + if (isConfirmed(cf)) { + fail('Evidence', `${at}: confirmed, but no source_url — a reader cannot check the quote`); + bad++; + } else { + warn('Evidence', `${at}: drafted without a source_url — add one before confirmation`); + } + } + }); + } + + const { orphans, summary } = deriveEvidence(readEntries(ROOT), incidents); + for (const o of orphans) { + warn('Evidence', `${o.incident}: ${o.framework} ${o.control_id} failed, but none of ${o.entries.join(', ')} maps it — missing mapping? (human call, C4)`); + } + + if (!bad) { + pass('Evidence', `${total} control failure(s) resolve to registry controls with a basis — ${summary.confirmed} confirmed, ${summary.drafted} drafted`); + } + return bad === 0; +} + function run() { const args = process.argv.slice(2); const quickMode = args.includes('--quick');