Researchers disclosed a supply-chain weakness in the ClawHub AI plugin registry after finding 23 unauthorized, code-executing plugins published under official-looking scopes including @openclaw/ and @clawhub/. Manifold Security reported that ClawHub did not consistently reserve those namespaces for legitimate owners across all existing packages, allowing unrelated accounts to publish plugins that appeared to be first-party tools for ClawHub, OpenClaw, and other agent ecosystems. The reviewed plugins were not confirmed to contain malicious code, but they still ran inside agent environments, creating a trust and impersonation risk for users who relied on scope names as proof of authenticity.
Several of the exposed plugins carried high-risk capabilities, including payment processing, host-level Git execution, configuration export, and access to external APIs, underscoring the potential impact if a malicious actor abused the same gap. After disclosure, ClawHub unlisted all 23 plugins, changed registry handling, and added a dispute process for unauthorized namespace usage. The case highlights broader security gaps emerging in AI tool and plugin registries, where weak publication-time ownership checks can turn official branding cues into a software supply-chain attack surface.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers publicly disclosed that 23 plugins were published under official-looking ClawHub and OpenClaw scopes while being controlled by unrelated accounts, creating supply chain trust confusion in the AI plugin registry. The reviewed plugins were not necessarily malicious, but all executed code in agent environments and some exposed high-risk capabilities.
By June 19, ClawHub had unlisted all 23 unauthorized plugins and introduced a dispute process for unauthorized namespace usage. Another report also states that ClawHub changed the registry after disclosure.
Manifold Security reported to ClawHub that 23 unauthorized code-executing plugins had been published under official-looking @openclaw and @clawhub scopes due to inconsistent namespace ownership enforcement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcemanifold.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.