Infostealer harvests configuration files from an AI agent
Security firm Hudson Rock has observed a real-world case of infostealer malware exfiltrating configuration files from an OpenClaw AI agent. The malware had no dedicated OpenClaw module but performed a broad file sweep that captured key files in the .openclaw directory, including openclaw.json, device.json and soul.md. These hold authentication tokens, cryptographic keys and behavioural data defining the agent's identity and operation. Stolen tokens could allow remote access or impersonation of the agent, and private keys could let attackers spoof trusted devices or reach paired services. Hudson Rock expects infostealers to develop dedicated modules for such configurations as AI assistants become more widely used.
What this means for your organisation
AI agents are typically given access to email, files, code and internal services on an employee's behalf. The configuration governing that access sits as ordinary files on the machine and is rarely covered by any access control. An infected laptop can therefore give an attacker not only the user's password but the agent's permissions, which are often broader. This is a concrete argument for bringing AI tooling into normal governance rather than letting it live alongside it.
Berigo recommends
- Get an overview of which AI agents are in use across the organisation and what access they actually hold.
- Give agents their own scoped, short-lived credentials instead of inheriting the user's full permissions.
- Bring agent configuration and key files into detection rules so that reading them raises an alert.
- Establish a routine to revoke agent tokens and keys when a machine is suspected of infection.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch