Technology
- Home
- Technology
- News
The AI security nightmare is here and it looks suspiciously like lobster
A hacker tricked a popular AI coding tool into installing OpenClaw - the viral, open-source AI agent OpenClaw that "actually does things" - absolutely everywhere. Funny as a stunt, but a sign of what to come as more and more people let autonomous software use…

Published 2 days ago on Feb 22nd 2026, 2:00 pm
By Web Desk

A hacker tricked a popular AI coding tool into installing OpenClaw — the viral, open-source AI agent OpenClaw that “actually does things” — absolutely everywhere. Funny as a stunt, but a sign of what to come as more and more people let autonomous software use their computers on their behalf.
The hacker took advantage of a vulnerability in Cline, an open-source AI coding agent popular among developers, that security researcher Adnan Khan had surfaced just days earlier as a proof of concept. Simply put, Cline’s workflow used Anthropic’s Claude, which could be fed sneaky instructions and made to do things that it shouldn’t, a technique known as a prompt injection.
The hacker used their access to slip through instructions to automatically install software on users’ computers. They could have installed anything, but they opted for OpenClaw. Fortunately, the agents were not activated upon installation, or this would have been a very different story.
It’s a sign of how quickly things can unravel when AI agents are given control over our computers. They may look like clever wordplay — one group wooed chatbots into committing crimes with poetry — but in a world of increasingly autonomous software, prompt injections are massive security risks that are very difficult to defend against. Acknowledging this, some companies instead lock down what AI tools can do if they’re hijacked. OpenAI, for example, recently introduced a new Lockdown Mode for ChatGPT preventing it from giving your data away.
Obviously, protecting against prompt injections is harder if you ignore the researchers who privately flag flaws to you. Khan said he warned Cline about the vulnerability weeks before publishing his findings. The exploit was only fixed after he called them out publicly.

Pakistan, Bangladesh to expand cooperation across diverse sectors
- ایک دن قبل

President, PM urge Scouts to assist Govt in dealing with challenges
- 2 دن قبل
Iran says any US attack including limited strikes would be ‘act of aggression’
- 11 گھنٹے قبل
T20 World Cup: Pakistan warn England’s flaky batting to expect a trial by spin
- 11 گھنٹے قبل

Pakistan targets 7 TTP, ISKP hideouts in border operation
- 2 دن قبل
Security forces neutralise four Indian-sponsored terrorists in Pishin IBO: ISPR
- 12 گھنٹے قبل
Three Federal Constabulary personnel martyred in terrorist attack in KP’s Karak
- 11 گھنٹے قبل

What are gold rates in Pakistan, global markets today?
- 12 گھنٹے قبل

The Supreme Court just blew up Trump’s foreign policy
- 2 دن قبل
UN chief decries global rise of ‘rule of force’
- 9 گھنٹے قبل

Super eight: spinners’ magic works as England beat Sri Lanka by 51 runs
- ایک دن قبل

Punjab aircraft controversy should be viewed through facts and policy lens: Analysts
- 2 دن قبل
You May Like
Trending









