Switch language한국어
Back to the list

The Worst Morning of My Developer Life — A Patient Hacker, a Fake AI Tool, and 150 Deleted Repos — My Story

TL;DR AI

Key summary

2 min read
  1. A developer found over 150 GitHub repositories deleted and replaced with ransom-note repos on March 24, 2026.

  2. The attacker chain began after the developer installed an npm package called OpenClaw that created a persistent gateway on macOS.

  3. OpenClaw accessed shell history, exposed a GitHub Personal Access Token, and the attacker used it to remove integrations and delete repos.

  4. The gateway had run for seven days and the activity traced to IP 188.241.177.181 in São Paulo, Brazil.

  5. The developer revoked tokens, opened a GitHub emergency ticket, and investigated LaunchAgents and running connections.

Read the original