Web Hack List

Preliminary research

Thinking Outside The Box: Exfiltrating OpenClaw Data from NVIDIA's new Sandbox

Exfiltrating OpenClaw Data from NVIDIA's new Sandbox

AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from April through September. Unranked, incomplete, not community-vetted, and subject to change.

Demonstrates that static egress allowlists do not contain an agent that can misuse already approved services. Malicious dependencies probe and reuse permitted GitHub, npm and messaging channels to exfiltrate NemoClaw data, then persist by poisoning agent configuration while staying inside the sandbox's nominal network policy.

Record

Document
Exfiltrating OpenClaw Data from NVIDIA's new Sandbox
Researcher
Noy Pearl
Published by
Lasso Security

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Noy Pearl, first published at the original source. Preserved copies are kept so the citation survives its host.