23 ClawHub plugins squatting official scopes expose AI registry security gaps

2026-06-22T08:51:46Zbeb420997b235955cde693af740266cb994d0d9ed62dd3ecfc10ab16e05654c7
AI agentsAgent BeaconFortinet credentialsGitHub abuseKlue breachLLM APISplunk RCEVirusTotal abuseYouTube abusecredential leakagecrypto-stealer malwaredata theftencrypted DNSiOS appsnpm scopesplugin registrysoftware TPMsupply chainsystemd 261telemetry

What happened

Help Net Security roundup (22 Jun 2026): Researchers found 23 code-executing plugins on the ClawHub AI plugin registry squatting official @openclaw/@clawhub scopes, exposing registry/namespace management gaps that enable supply-chain and impersonation risks. Separately, Wake Forest University researchers discovered 282 iOS apps leaking LLM API credentials or backend access mechanisms, creating widespread exploitable backend exposures. Other coverage: an open-source telemetry project (Beacon) for AI agents; a study showing encrypted DNS still reveals flow metadata; systemd 261 release (adds a软件

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
beb420997b235955cde693af740266cb994d0d9ed62dd3ecfc10ab16e05654c7
Enrichment time
2026-06-22T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.