Malicious Code Detection
When an AI agent came knocking: Catching malicious contributions in Datadog’s open source repos | Datadog

When an AI agent came knocking: Catching malicious contributions in Datadog’s open source repos | Datadog

3/9/2026 · Christoph Hamsen, Kylian Serrania, Christophe Tafani-Dereeper

What this post added

This post details how Datadog's BewAIre system, previously focused on malicious code in PRs, was enhanced to detect AI agent-driven attacks targeting open-source repositories and CI/CD workflows. It describes the identification of the hackerbot-claw AI agent and its attempts to exploit GitHub Actions and LLM-powered workflows. The post highlights the system's ability to validate existing defensive controls and the subsequent hardening of systems to address these new threats, including the integration of security signals into Cloud SIEM and incident response workflows.

Read the original post ↗