ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
2026-03-05T14:23:06Z•d3aad496e2f42d526135f7315edc5f9547ebfec13745a2c74ab27754059e664c
active-exploitationair-gapped-exfiltrationbackdoorblockchain-c2botnetcloud-api-keyscredential-exposuredeveloper-targetingdoj-seizureincident-responsemalicious-packagesremote-code-executionsupply-chain-riskthreat-actor-activityvulnerability-disclosure
What happened
A wide-ranging set of security incidents and disclosures across February 2026: multiple active, high-severity vulnerabilities (notably Cisco SD‑WAN CVE-2026-20127 exploited in the wild and FileZen CVE-2026-25108 added to CISA KEV), SolarWinds Serv-U patched several critical RCEs (including CVE-2025-40538), and OpenClaw fixed a local-agent WebSocket hijack dubbed “ClawJacked.” Supply-chain and credential exposures are prominent — Google Cloud API keys found in client-side code allowed access to Gemini endpoints, malicious open-source packages and trojanized repos targeted developers (malicious·
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d3aad496e2f42d526135f7315edc5f9547ebfec13745a2c74ab27754059e664c
- Enrichment time
- 2026-03-05T14:23:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.