Scan to download
BTC $64,056.43 +1.52%
ETH $1,676.51 +1.34%
BNB $608.42 +0.68%
XRP $1.13 +1.79%
SOL $67.95 +2.04%
TRX $0.3171 +1.37%
DOGE $0.0880 +1.47%
ADA $0.1737 +3.36%
BCH $208.69 +3.17%
LINK $7.98 +2.04%
HYPE $59.01 -0.87%
AAVE $66.83 +4.33%
SUI $0.7669 +2.39%
XLM $0.1884 -0.78%
ZEC $412.22 -3.04%
BTC $64,056.43 +1.52%
ETH $1,676.51 +1.34%
BNB $608.42 +0.68%
XRP $1.13 +1.79%
SOL $67.95 +2.04%
TRX $0.3171 +1.37%
DOGE $0.0880 +1.47%
ADA $0.1737 +3.36%
BCH $208.69 +3.17%
LINK $7.98 +2.04%
HYPE $59.01 -0.87%
AAVE $66.83 +4.33%
SUI $0.7669 +2.39%
XLM $0.1884 -0.78%
ZEC $412.22 -3.04%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56
Collection

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.