BTC $64,770.14 +2.18%
ETH $1,922.06 +2.12%
BNB $594.02 +4.69%
XRP $1.08 +2.35%
SOL $74.69 +2.74%
TRX $0.3287 +1.04%
DOGE $0.0706 +1.76%
ADA $0.1722 +5.78%
BCH $218.70 +6.62%
LINK $8.48 +3.36%
HYPE $55.40 +3.50%
AAVE $99.39 +2.97%
SUI $0.7000 +2.96%
XLM $0.1729 +2.38%
ZEC $475.15 +3.19%
BTC $64,770.14 +2.18%
ETH $1,922.06 +2.12%
BNB $594.02 +4.69%
XRP $1.08 +2.35%
SOL $74.69 +2.74%
TRX $0.3287 +1.04%
DOGE $0.0706 +1.76%
ADA $0.1722 +5.78%
BCH $218.70 +6.62%
LINK $8.48 +3.36%
HYPE $55.40 +3.50%
AAVE $99.39 +2.97%
SUI $0.7000 +2.96%
XLM $0.1729 +2.38%
ZEC $475.15 +3.19%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56
Collection

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.