Security researchers found hundreds of malicious add-ons on ClawHub.
Active React2Shell exploitation uses malicious NGINX configurations to hijack web traffic, targeting Baota panels, Asian TLDs, and government domains.