BTC $64,773.19 +1.13%
ETH $1,922.15 +1.10%
BNB $594.24 +4.22%
XRP $1.08 +0.58%
SOL $74.58 +1.53%
TRX $0.3285 +1.05%
DOGE $0.0708 +0.54%
ADA $0.1723 +3.15%
BCH $218.60 +4.15%
LINK $8.49 +2.08%
HYPE $55.16 +1.73%
AAVE $100.02 +1.22%
SUI $0.7004 +1.57%
XLM $0.1727 +0.65%
ZEC $472.96 +1.97%
BTC $64,773.19 +1.13%
ETH $1,922.15 +1.10%
BNB $594.24 +4.22%
XRP $1.08 +0.58%
SOL $74.58 +1.53%
TRX $0.3285 +1.05%
DOGE $0.0708 +0.54%
ADA $0.1723 +3.15%
BCH $218.60 +4.15%
LINK $8.49 +2.08%
HYPE $55.16 +1.73%
AAVE $100.02 +1.22%
SUI $0.7004 +1.57%
XLM $0.1727 +0.65%
ZEC $472.96 +1.97%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56
Collection

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.