Unauthorized Scope Squatting Exposes ClawHub Registry Vulnerabilities

Unauthorized Scope Squatting Exposes ClawHub Registry Vulnerabilities

2h ago Feeds2.FeedburnerFeeds.4Sysops 86% similarity 64.5
Share:

Article Content

Browse articles
ThreatCluster

ClawHub, a plugin registry for AI agents, has been compromised by unauthorized accounts publishing plugins under official scopes like @openclaw and @clawhub. This security gap allows malicious actors to exploit the trust associated with these namespaces, potentially leading to the distribution of harmful code. A total of 23 plugins were found to be executing code under these official scopes, raising significant concerns about the integrity of the registry. The lack of enforcement mechanisms for scope reservations has left users vulnerable to attacks. Affected users include developers and organizations relying on ClawHub for trusted AI plugins. The current status indicates ongoing scrutiny of the registry's security practices. Immediate action is recommended to mitigate risks associated with these unauthorized plugins.

Key Points: • 23 unauthorized plugins were published under official ClawHub scopes. • The lack of enforcement allowed malicious actors to exploit trust signals. • Developers using ClawHub are at risk of executing potentially harmful code.

ThreatCluster AI

Timeline

2026-06-22
Unauthorized plugins discovered on ClawHub
23 plugins were found squatting under official scopes, posing security risks to users relying on ClawHub.
Feeds2.Feedburner
2026-06-22
Security gaps in ClawHub registry reported
Reports highlighted the lack of enforcement for npm-style scopes, allowing unauthorized accounts to publish plugins.
Feeds.4Sysops

Community

Browse all →