ACVEAgent configuration vulnerability registry

Current conditions

Campaigns are living records: a new package, extension, repository or host that belongs to a known operation extends the timeline; status is derived from the last branch date.

1 active · 9 dormant · 0 contained

Active campaigns

Agent credential stealers (active)

Infostealer branches increasingly target agent tokens, sessions, wallets, and MCP files.

2026-02-13 → 2026-09-01 · 3 branches · openvsx, vscode-marketplace, github, other

Latest: 2026-09-01 · report · claude-session-cookies · source

What to check: OpenClaw or a known fake agent extension is present

Linked advisories: ACVE-2026-0415, ACVE-2026-0416, ACVE-2026-0417

Dormant campaigns

n4d mesh (dormant)

Shodan-driven MCP command loops harvested exposed AI infrastructure credentials.

2026-07-01 → 2026-07-01 · 1 branches · internet-exposed, ollama, github

Latest: Jul 2026 (approx.) · exposure · mcp-execute_command-loop · source

What to check: MCP exposes execute_command alongside a public AI service

Linked advisories: ACVE-2026-0420

GlassWorm (dormant)

Developer-tooling malware spread through extensions and package branches.

2025-10-01 → 2026-05-26 · 2 branches · openvsx, vscode-marketplace, npm, pypi, github

Latest: 2026-05-26 · report · glassworm-takedown · source

What to check: Open VSX or VS Code marketplace plugins are installed

Linked advisories: ACVE-2026-0413

TeamPCP supply-chain campaign (dormant)

Poisoned LiteLLM releases harvested build and cloud secrets.

2026-03-24 → 2026-03-24 · 2 branches · pypi, github

Latest: 2026-03-24 · package · litellm@1.82.8 · source

What to check: LiteLLM 1.82.7 or 1.82.8 is installed

Linked advisories: ACVE-2026-0404

OpenClaw Control UI exposure (dormant)

Internet-exposed OpenClaw Control UI instances permit token exfiltration and one-click RCE.

2026-02-01 → 2026-02-01 · 1 branches · internet-exposed, github

Latest: Feb 2026 (approx.) · exposure · 135000-openclaw-hosts · source

What to check: OpenClaw Control UI is reachable from an untrusted network

Linked advisories: ACVE-2026-0421

ClawHavoc (dormant)

Malicious OpenClaw skills delivered stealers and backdoors.

2026-01-27 → 2026-01-27 · 1 branches · clawhub, github

Latest: 2026-01-27 · skill · 341/2857-clawhub-skills · source

What to check: Skills are installed from ClawHub

Linked advisories: ACVE-2026-0414

Operation Bizarre Bazaar (Hecker LLMjacking) (dormant)

Exposed LLM endpoints were hijacked and resold for LLM access.

2025-10-01 → 2026-01-01 · 3 branches · ollama, internet-exposed

Latest: Jan 2026 (approx.) · report · silver-inc-marketplace · source

What to check: Ollama is bound off loopback without an authentication proxy

Linked advisories: ACVE-2026-0407

postmark-mcp (dormant)

Multiple malicious postmark-mcp versions BCCed mail to the publisher.

2025-09-17 → 2025-09-25 · 2 branches · npm

Latest: 2025-09-25 · report · 1643-installs · source

What to check: postmark-mcp is installed as an MCP server

Linked advisories: ACVE-2026-0408

Nx s1ngularity (dormant)

Nx postinstall code invoked agent CLIs with permission-bypass flags to steal secrets.

2025-08-27 → 2025-08-28 · 2 branches · npm, github

Latest: 2025-08-28 · report · 1079-systems-2349-secrets · source

What to check: Agent tools include bash, a Claude Code or Gemini CLI harness, and never approval

Linked advisories: ACVE-2026-0405