Current conditions
Campaigns are living records: a new package, extension, repository or host that belongs to a known operation extends the timeline; status is derived from the last branch date.
1 active · 9 dormant · 0 contained
Active campaigns
Agent credential stealers (active)
Infostealer branches increasingly target agent tokens, sessions, wallets, and MCP files.
Latest: 2026-09-01 · report · claude-session-cookies · source
What to check: OpenClaw or a known fake agent extension is present
Linked advisories: ACVE-2026-0415, ACVE-2026-0416, ACVE-2026-0417
Dormant campaigns
n4d mesh (dormant)
Shodan-driven MCP command loops harvested exposed AI infrastructure credentials.
Latest: Jul 2026 (approx.) · exposure · mcp-execute_command-loop · source
What to check: MCP exposes execute_command alongside a public AI service
Linked advisories: ACVE-2026-0420
GlassWorm (dormant)
Developer-tooling malware spread through extensions and package branches.
Latest: 2026-05-26 · report · glassworm-takedown · source
What to check: Open VSX or VS Code marketplace plugins are installed
Linked advisories: ACVE-2026-0413
Hugging Face pickle and loader waves (dormant)
Recurring malicious-model, namespace, pickle, and loader-lure branches on Hugging Face.
Latest: May 2026 (approx.) · repo · hf:Open-OSS/privacy-filter · source
What to check: A Hugging Face model is loaded with remote or pickle code enabled
Linked advisories: ACVE-2026-0301, ACVE-2026-0303, ACVE-2026-0304, ACVE-2026-0305, ACVE-2026-0307, ACVE-2026-0308, ACVE-2026-0309, ACVE-2026-0310
TeamPCP supply-chain campaign (dormant)
Poisoned LiteLLM releases harvested build and cloud secrets.
Latest: 2026-03-24 · package · litellm@1.82.8 · source
What to check: LiteLLM 1.82.7 or 1.82.8 is installed
Linked advisories: ACVE-2026-0404
OpenClaw Control UI exposure (dormant)
Internet-exposed OpenClaw Control UI instances permit token exfiltration and one-click RCE.
Latest: Feb 2026 (approx.) · exposure · 135000-openclaw-hosts · source
What to check: OpenClaw Control UI is reachable from an untrusted network
Linked advisories: ACVE-2026-0421
ClawHavoc (dormant)
Malicious OpenClaw skills delivered stealers and backdoors.
Latest: 2026-01-27 · skill · 341/2857-clawhub-skills · source
What to check: Skills are installed from ClawHub
Linked advisories: ACVE-2026-0414
Operation Bizarre Bazaar (Hecker LLMjacking) (dormant)
Exposed LLM endpoints were hijacked and resold for LLM access.
Latest: Jan 2026 (approx.) · report · silver-inc-marketplace · source
What to check: Ollama is bound off loopback without an authentication proxy
Linked advisories: ACVE-2026-0407
postmark-mcp (dormant)
Multiple malicious postmark-mcp versions BCCed mail to the publisher.
Latest: 2025-09-25 · report · 1643-installs · source
What to check: postmark-mcp is installed as an MCP server
Linked advisories: ACVE-2026-0408
Nx s1ngularity (dormant)
Nx postinstall code invoked agent CLIs with permission-bypass flags to steal secrets.
Latest: 2025-08-28 · report · 1079-systems-2349-secrets · source
What to check: Agent tools include bash, a Claude Code or Gemini CLI harness, and never approval
Linked advisories: ACVE-2026-0405