logo

ClawHub Scope Squatting Lets Plugins Masquerade as Official OpenClaw Integrations

ID: a20b7f0f-a31d-532b-bd80-2bbfda78119f

STIX ID: report--a20b7f0f-a31d-532b-bd80-2bbfda78119f

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Mayura Kathir

...
...

Manifold discovered a scope‑squatting weakness in ClawHub’s plugin registry that permitted third‑party publishers to register code‑executing plugins under official organizational scopes (such as @openclaw and @clawhub), creating a provenance‑based impersonation risk. Although no obviously malicious payloads were found in the reviewed packages, these plugins can execute sensitive actions inside agents (payments, host git/gh commands, egress to APIs), and ClawHub has since unlisted misleading plugins and implemented a namespace‑claim dispute process.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.