Cybercriminals are exploiting the popularity of OpenClaw to launch a phishing campaign targeting developers on GitHub (with the bait of free crypto tokens). According to a disclosure by OX Security, the campaign involves fake “CLAW” token airdrops promising rewards of thousands of dollars. Developers are lured into malicious repositories and discussions on GitHub and eventually redirected to convincing fake websites that ask them to crypto wallets their.

“The malicious actor opens issues in repositories controlled by the attacker and tags GitHub users to maximize visibility and reach,” OX researchers said in a post. “The associated website is almost identical to openclaw.aibuttonconnect your walletdesigned to initiate wallet theft.”
See also: GlassWorm malware hides RAT in Chrome extension
Researchers reported that the malicious actor created multiple accounts for the campaign and deleted them all within hours of its launch. Analysis showed that no users have yet been affected by the campaign.
Abuse of GitHub by cybercriminals
The campaign moves phishing into GitHub workflows, which is not very common. The attackers created or took over repositories, filled them with attractive content, and amplified their reach by tagging developers or participating in discussions to increase visibility. The campaign uses a layer of social engineering, which includes legitimate-looking issues, pull requests, and repo mentions.
GitHub was likely chosen because developers trust the platform. They are more likely to click on a bait that is spread in a familiar environment.
Victims are initially attracted via GitHub issues that state: “We appreciate your contributions to GitHub. We have analyzed profiles and selected developers to receive OpenClaw allocation.” The message is worded as a limited-time token giveaway, worth $5000 in CLAW tokens. It directs users to collect the tokens by visiting the malicious website.

“We estimate that attackers may be using star feature to identify users who have starred OpenClaw-related repositories and specifically target them. Thus, the phishing campaign appears more credible and relevant to the recipients,” the researchers added.
CLAW is not a legitimate token and is being promoted as a new release as part of a scam. In fact, OpenClaw developer Peter Steinbergerhas explicitly stated in the past that the project will never issue tokens and any statement to the contrary is a scam.
See also: WebRTC Skimmer bypasses CSP and steals payment data
Smart, stealthy malicious code
According to OX, the malicious phishing code is not easily detected and is located within the JavaScript file “eleven.js” in the repository.
The malicious actor used “watery-compost[.]today” to host a C2 server, to collect information (including wallet address, transaction value, and name) and empty wallets once they are connected. Commands used by the C2 include PromtTx, Approved, and Declined.
Additionally, the malicious code includes a “nuke” function that deletes stolen wallet information from the browser’s local storage to avoid detection and analysis. The address “0x6981E9EA7023a8407E4B08ad97f186A5CBDaFCf5” was extracted from the code and identified as the malicious actor’s wallet used to receive stolen cryptocurrencies.
See also: Device code phishing attack has targeted 340+ organizations
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The phishing page (“token-claw[.]xyz”) is said to support multiple crypto wallets, including WalletConnect, MetaMask, Trust Wallet, OKX Wallet, and Bybit Wallet. OX researchers recommended blocking the phishing domain from all environments, avoiding connecting crypto wallets to untrusted websites, and treating token giveaway issues from unknown sources as suspicious.
Users should also review any recent wallet connections related to the campaign and revoke all approvals immediately.
