23 ClawHub plugins squatting official scopes expose AI registry security gaps
2026-06-22T08:51:46Z•beb420997b235955cde693af740266cb994d0d9ed62dd3ecfc10ab16e05654c7
AI agentsAgent BeaconFortinet credentialsGitHub abuseKlue breachLLM APISplunk RCEVirusTotal abuseYouTube abusecredential leakagecrypto-stealer malwaredata theftencrypted DNSiOS appsnpm scopesplugin registrysoftware TPMsupply chainsystemd 261telemetry
What happened
Help Net Security roundup (22 Jun 2026): Researchers found 23 code-executing plugins on the ClawHub AI plugin registry squatting official @openclaw/@clawhub scopes, exposing registry/namespace management gaps that enable supply-chain and impersonation risks. Separately, Wake Forest University researchers discovered 282 iOS apps leaking LLM API credentials or backend access mechanisms, creating widespread exploitable backend exposures. Other coverage: an open-source telemetry project (Beacon) for AI agents; a study showing encrypted DNS still reveals flow metadata; systemd 261 release (adds a软件
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- beb420997b235955cde693af740266cb994d0d9ed62dd3ecfc10ab16e05654c7
- Enrichment time
- 2026-06-22T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.