No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Moltbot (Formerly Clawdbot) Already Has a Malware Problem

January 29, 2026
in Protection
0
Moltbot (Formerly Clawdbot) Already Has a Malware Problem



Moltbot (formerly known as Clawdbot) is the most viral AI product I’ve seen in a while. The personal AI assistant runs locally and connects via a chat app, like WhatsApp or iMessage. Once you give Moltbot access to your entire device, it can do things on that device for you. This the sort of thing that excites agentic AI pioneers, but worries privacy and security enthusiasts like myself.

And indeed, I have significant concerns about the risks installing Moltbot on your personal machine. Since agentic AI will autonomously perform tasks based on prompts, bad actors can take advantage of the situation by surreptitiously feeding those bots malicious prompts of their own. This is called prompt injection, and it can impact any type of agentic AI system, whether an AI browser, or an AI assistant like Moltbot.

But it’s not just prompt injection that presents an issue for Moltbot users.

Someone has already created a malicious Moltbot extension

As spotted by The Hacker News, Moltbot already has its first malicious extension, dubbed “Clawdbot Agent – AI Coding Assistant” (“clawdbot.clawdbot-agent.”) It seems to have been developed before the bot’s name change. This extension is designed for Visual Studio Code, Microsoft’s open source AI code editor. What’s worse, it was hosted on Microsoft’s official Extension Marketplace, which no doubt gave it legitimacy to Moltbot users looking for a Visual Studio Code extension.

The extension advertised itself as a free AI coding assistant. When you install it, it executes a series of commands that ends up running a remote desktop program (The Hacker News says it’s “ConnectWise ScreenConnect”) on your device. It then connects to a link that lets the bad actor gain remote access to your device. By just installing this extension, you essentially give the hacker the tools to take over your computer from wherever they are.

Luckily, Microsoft has already taken action. The extension is no longer available on the marketplace as of Tuesday. Moltbot has no official Visual Studio Code extension, so assume any you see are illegitimate at best, and malicious at worst. If you did install the extension, researchers have detailed instructions for removing the malware and blocingk any of its processes from running on your device. Of course, to first thing to do is uninstall the extension from Visual Studio Code immediately.

Moltbolt has more security issues too

The Hacker News goes on to highlight findings from security researcher Jamieson O’Reilly, who discovered hundreds of unauthenticated Moltbot instances readily available on the internet. These instances reveal Moltbot users’ configuration data, API keys, OAuth credentials, and even chat histories.


What do you think so far?

Bad actors could use these instances for prompt injection: They could pretend to be a Moltbot user, and issue their own prompts to that user’s Moltbot AI assistant, or manipulate existing prompts and responses. They could also upload malicious “skills,” or specific collections of context and knowledge, to MoltHub and use them to attack users and steal their data.

Speaking to The Hacker News, security researcher Benjamin Marr explains that the core issue is how Moltbot is designed for “ease of deployment” over a “secure-by-default” set up. You can poke around with Moltbot and install sensitive programs without the bot ever warning you about the security risks. There should be firewalls, credential validation, and sandboxing in the mix, and without those things, the user is at greater risk.

To combat against this, The Hacker News recommends that all Moltbot users running with the default security configurations take the following steps:

  • remove any connected service integrations

  • check exposed credentials

  • set up network controls

  • look for any signs of attack

Or, you could do what I’m doing, and avoid Moltbot altogether.



Editorial Team

Editorial Team

Related Posts

The Xteink X4 E-Reader Is Under $60 on Amazon for the Next Few Hours
Protection

The Xteink X4 E-Reader Is Under $60 on Amazon for the Next Few Hours

April 25, 2026
What 'Zone 2' Cardio Actually Means
Protection

What ‘Zone 2’ Cardio Actually Means

April 25, 2026
The Sony WH-CH720N Noise-Canceling Headphones Are Nearly Half Off
Protection

The Sony WH-CH720N Noise-Canceling Headphones Are Nearly Half Off

April 25, 2026
10 Hacks Every YouTube Music User Should Know
Protection

10 Hacks Every YouTube Music User Should Know

April 25, 2026
ChatGPT's Latest Update Makes It Harder Than Ever to Spot AI-Generated Images
Protection

ChatGPT’s Latest Update Makes It Harder Than Ever to Spot AI-Generated Images

April 24, 2026
The Xteink S4 Might Be the Pocket E-Reader of My Dreams
Protection

The Xteink S4 Might Be the Pocket E-Reader of My Dreams

April 24, 2026
Load More
Next Post
INTC, T, LRN, ELV, TXT & more

INTC, T, LRN, ELV, TXT & more

Popular News

  • Questrade’s 4% Cash Back Offer – Millennial Revolution

    Questrade’s 4% Cash Back Offer – Millennial Revolution

    0 shares
    Share 0 Tweet 0
  • Volkswagen announces voice AI in its Chinese cars from later this year

    0 shares
    Share 0 Tweet 0
  • BOK New Governor Signals CBDC Push

    0 shares
    Share 0 Tweet 0
  • Galaxy Enhance-X Is Samsung’s Best Photo and Video Editing Tool

    0 shares
    Share 0 Tweet 0
  • Why You Should Be Paying Attention To The Bitcoin Monthly MACD

    0 shares
    Share 0 Tweet 0

Latest News

Crypto Scammer Tied to UK Drug Seizure

Crypto scam launderer gets 70 months as DOJ cracks down

April 26, 2026
0

Evan Tangeman, a 22-year-old California resident, has been sentenced to 70 months in prison for his role in a crypto...

US crude exports hit record 5.2M barrels amid Iran conflict

US crude exports hit record 5.2M barrels amid Iran conflict

April 26, 2026
0

US crude exports have reached a record 5.2 million barrels per day during the ongoing Iran conflict. The US-Iran nuclear...

Coordinator, Educational Programs, Apprenticeships & School-to-Work

Coordinator, Educational Programs, Apprenticeships & School-to-Work

April 26, 2026
0

Job Description: The Coordinator, Educational Programs manages the holistic development and academic success of students in the...

Factbox-Who is Cole Allen, the suspect in the White House Correspondents’ Dinner shooting?

Factbox-Who is Cole Allen, the suspect in the White House Correspondents’ Dinner shooting?

April 26, 2026
0

Factbox-Who is Cole Allen, the suspect in the White House Correspondents’ Dinner shooting?

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.