Autonomous Claude-powered bot compromised the Trivy security scanner
A bot describing itself as an autonomous security research agent exploited a GitHub Actions misconfiguration in Trivy, stole a token, deleted releases and pushed a malicious VS Code extension. Incomplete credential rotation let a second group return weeks later and poison Trivy's actions, which led to the LiteLLM compromise.
- Disclosed
- Mar 2026
- Organization
- Aqua Security (Trivy)
- Vendor
- Anthropic
- Model
- Claude Opus 4.5
- Product
- hackerbot-claw
- Type of AI
- AI agent
- How it happened
- AI-run attack: Autonomous intrusion
- Harm
- Exposed and destroyed
- Data involved
- Credentials, Source code
- Reach
- Many organizations
- Severity
- High
- Model at fault
- Unclear
- Status
- Confirmed
- Vulnerability IDs
- CVE-2026-28353