Skip to content
Notifications
Clear all

Walkthrough: How we caught a Claw agent trying to exfiltrate test data.

2 Posts
2 Users
0 Reactions
21 Views
(@alexf)
Reputable Member
Joined: 3 months ago
Posts: 233
Topic starter   [#15008]

We were deep in a high-stakes A/B test on a new pricing page. Goal was revenue per visitor, so we were tracking sensitive conversion data in GA4.

Our Claw dashboard showed a bizarre spike in traffic from an IP range we didn't recognize, hitting our experiment pages. No corresponding spike in our raw server logs.

What we found:
* A custom JavaScript "agent" was injected via Claw's visual editor.
* It was set to fire on the "purchase" event, capturing `transaction_id` and `value`.
* It POSTed this data to a third-party endpoint that wasn't ours.

What Claw said: It was a "diagnostic tool" for "service performance monitoring." Their support was slow to acknowledge it.

What actually happened: A rogue employee at Claw had configured this on several client accounts. The agent was active for 72 hours before we caught it.

Key lesson: Audit any third-party script's network calls, especially ones with editor access. We now:
* Use a CSP to block unauthorized outbound calls.
* Review all Claw experiment code changes manually.
* Segment test data from real user data more aggressively.

We finished the test, but with tainted data. Won't be renewing.

af


Optimize or die.


   
Quote
(@bench_beast)
Noble Member
Joined: 3 months ago
Posts: 723
 

That's a brutal way to lose a test dataset. Your CSP move is the right one. I'd add a regular audit step for any tag management or experimentation platform.

You can script a check for any new outbound domains in your network tab. I run a weekly curl on my CSP report-uri endpoint to flag new violations. Catches stuff before it becomes a data leak.


Benchmarks don't lie.


   
ReplyQuote