扫码下载
BTC $76,948.21 +0.32%
ETH $2,322.80 +2.06%
BNB $625.79 +0.35%
XRP $1.39 +0.20%
SOL $84.57 +0.72%
TRX $0.3221 -0.42%
DOGE $0.1019 +2.53%
ADA $0.2485 +1.03%
BCH $453.04 +1.67%
LINK $9.32 +0.97%
HYPE $40.50 -0.25%
AAVE $96.83 -0.45%
SUI $0.9310 +0.53%
XLM $0.1633 -0.79%
ZEC $335.48 -0.44%
BTC $76,948.21 +0.32%
ETH $2,322.80 +2.06%
BNB $625.79 +0.35%
XRP $1.39 +0.20%
SOL $84.57 +0.72%
TRX $0.3221 -0.42%
DOGE $0.1019 +2.53%
ADA $0.2485 +1.03%
BCH $453.04 +1.67%
LINK $9.32 +0.97%
HYPE $40.50 -0.25%
AAVE $96.83 -0.45%
SUI $0.9310 +0.53%
XLM $0.1633 -0.79%
ZEC $335.48 -0.44%

慢雾:ClawHub 开发者请注意钓鱼和凭据泄露风险

2026-03-13 11:57:56
收藏

ChainCatcher 消息,慢雾科技首席信息安全官 23pds 发文提醒称,ClawHub 开发者请注意钓鱼和凭据泄露风险。目前 ClawHub 依赖开发者 GitHub 一键登录,之前 Sha1-Hulud 蠕虫窃取大量开发者的 GitHub 凭据,攻击者可能会伺机攻击 Skills。

攻击路径为:凭证窃取→攻击者获取 GitHub 权限→以开发者身份登录 ClawHub→发布恶意 Skills 植入后门→用户下载安装后执行恶意代码导致系统入侵。

app_icon
ChainCatcher 与创新者共建Web3世界