The AI security nightmare is here and it looks suspiciously like lobster
Source: The Verge
Overview
A hacker tricked a popular AI coding tool into installing OpenClaw — the viral, open‑source AI agent that “actually does things” — everywhere. While it may look like a stunt, it signals what’s to come as more people let autonomous software run on their computers.
Exploit details
The attacker exploited a vulnerability in Cline, an open‑source AI coding agent popular among developers. Security researcher Adnan Khan had disclosed the issue just days earlier as a proof of concept. Cline’s workflow relies on Anthropic’s Claude, which can be fed malicious instructions to perform actions it shouldn’t—a technique known as prompt injection.