logo

23 ClawHub plugins squatting official scopes expose AI registry security gaps

ID: dba6ea6b-3eff-5cab-b9c2-4fc7abf58790

STIX ID: report--dba6ea6b-3eff-5cab-b9c2-4fc7abf58790

Feed Name: Help Net Security

Threat Score
35/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Help Net Security

...
...

A security review found that ClawHub's plugin registry allowed 23 code-executing plugins to be published under official npm-style scopes (@openclaw and @clawhub) by unrelated accounts, creating a supply-chain and impersonation risk even though the code was not reported as malicious; the registry implemented changes after the issue was disclosed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.