Preliminary research
Thinking Outside The Box: Exfiltrating OpenClaw Data from NVIDIA's new Sandbox
Exfiltrating OpenClaw Data from NVIDIA's new Sandbox
AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from April through September. Unranked, incomplete, not community-vetted, and subject to change.
Demonstrates that static egress allowlists do not contain an agent that can misuse already approved services. Malicious dependencies probe and reuse permitted GitHub, npm and messaging channels to exfiltrate NemoClaw data, then persist by poisoning agent configuration while staying inside the sandbox's nominal network policy.
Record
- Document
- Exfiltrating OpenClaw Data from NVIDIA's new Sandbox
- Researcher
- Noy Pearl
- Published by
- Lasso Security
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Noy Pearl, first published at the original source. Preserved copies are kept so the citation survives its host.