
The Most Popular AI Agent on GitHub Is a Security Catastrophe
In November 2025, Austrian developer Peter Steinberger pushed a weekend project to GitHub. By February 2026, it had 200,000 stars, 42,000 exposed instances on the public internet, a supply chain poisoned with 1,184 malicious packages, and a CVE that let attackers take over any deployment with a single click. Then OpenAI hired him. OpenClaw — formerly Clawdbot, then Moltbot — is the fastest-growing open-source project in GitHub history. It's an autonomous AI agent that manages calendars, books flights, sends emails, executes code, and automates tasks across third-party services. Two million developers visited the documentation in a single week. Meta, Google, and dozens of Fortune 500 companies found employees running it on corporate endpoints. Cisco called it "groundbreaking from a capability perspective" and "an absolute nightmare from a security perspective." Both assessments are correct. The ClawHavoc Attack On January 25, 2026, security researcher Oren Yomtov at Koi Security audited
Continue reading on Dev.to DevOps
Opens in a new tab



