23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools
ID: cf68b209-912d-5a84-88fa-1c3cdb9877bb
STIX ID: report--cf68b209-912d-5a84-88fa-1c3cdb9877bb
Feed Name: cybersecurityNews.com
Researchers found 23 plugins on the ClawHub registry published under reserved @openclaw/@clawhub scopes by unrelated accounts (scope squatting), enabling code execution and high‑privilege actions inside AI agent environments; Manifold Security disclosed the issue on 2026‑06‑17, ClawHub unlisted the plugins on 2026‑06‑19 and added a namespace dispute process. No planted malicious code was found in reviewed versions, but the incident highlights a serious AI agent supply‑chain risk because future updates could introduce malicious behavior and many developers trust scoped plugin namespaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
