logo

23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools

ID: cf68b209-912d-5a84-88fa-1c3cdb9877bb

STIX ID: report--cf68b209-912d-5a84-88fa-1c3cdb9877bb

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-06-22

Date Updated: 2026-06-23

Author: Tushar Subhra Dutta

...
...

Researchers found 23 plugins on the ClawHub registry published under reserved @openclaw/@clawhub scopes by unrelated accounts (scope squatting), enabling code execution and high‑privilege actions inside AI agent environments; Manifold Security disclosed the issue on 2026‑06‑17, ClawHub unlisted the plugins on 2026‑06‑19 and added a namespace dispute process. No planted malicious code was found in reviewed versions, but the incident highlights a serious AI agent supply‑chain risk because future updates could introduce malicious behavior and many developers trust scoped plugin namespaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.