扫码下载
BTC $64,929.28 -2.45%
ETH $1,764.16 -1.09%
BNB $601.88 -2.30%
XRP $1.20 -3.32%
SOL $72.41 -3.44%
TRX $0.3185 +0.34%
DOGE $0.0859 -2.60%
ADA $0.1691 -5.86%
BCH $213.34 -5.76%
LINK $8.18 -1.96%
HYPE $72.97 -0.49%
AAVE $75.78 +0.64%
SUI $0.7907 -1.44%
XLM $0.2192 -0.84%
ZEC $504.47 -4.00%
BTC $64,929.28 -2.45%
ETH $1,764.16 -1.09%
BNB $601.88 -2.30%
XRP $1.20 -3.32%
SOL $72.41 -3.44%
TRX $0.3185 +0.34%
DOGE $0.0859 -2.60%
ADA $0.1691 -5.86%
BCH $213.34 -5.76%
LINK $8.18 -1.96%
HYPE $72.97 -0.49%
AAVE $75.78 +0.64%
SUI $0.7907 -1.44%
XLM $0.2192 -0.84%
ZEC $504.47 -4.00%

慢雾:ClawHub 开发者请注意钓鱼和凭据泄露风险

2026-03-13 11:57:56
收藏

ChainCatcher 消息,慢雾科技首席信息安全官 23pds 发文提醒称,ClawHub 开发者请注意钓鱼和凭据泄露风险。目前 ClawHub 依赖开发者 GitHub 一键登录,之前 Sha1-Hulud 蠕虫窃取大量开发者的 GitHub 凭据,攻击者可能会伺机攻击 Skills。

攻击路径为:凭证窃取→攻击者获取 GitHub 权限→以开发者身份登录 ClawHub→发布恶意 Skills 植入后门→用户下载安装后执行恶意代码导致系统入侵。

app_icon
ChainCatcher 与创新者共建Web3世界