OpenClaw Developers Targeted in GitHub Phishing Scam
- Attackers created fake GitHub accounts to deceive developers into believing they won $5,000 in $CLAW tokens.
- The phishing page used obfuscated JavaScript and a separate C2 server to drain connected wallets.
- No confirmed victims have been reported, and the fraudulent accounts were deleted within hours of creation.
- OpenClaw’s popularity surged after its acquisition by OpenAI, reaching over 323,000 GitHub stars.
- OX Security recommends blocking specific domains and treating token giveaways as suspicious.
The phishing campaign exploited OpenClaw’s recent rise in visibility following its integration with OpenAI, targeting developers by using fake GitHub accounts and cloned websites to steal funds from connected wallets. The attackers utilized advanced techniques such as obfuscated JavaScript to conceal their activities.
Despite the sophisticated nature of the scam, no victims have been confirmed yet, highlighting the effectiveness of early detection efforts by security platforms like OX Security. (Source)