BTC $79,128.57 -0.62%
ETH $2,488.51 +0.15%
BNB $739.75 -1.04%
XRP $1.40 -0.93%
SOL $104.09 -1.85%
TRX $0.3340 -0.34%
DOGE $0.0902 +1.22%
ADA $0.2212 +1.47%
BCH $262.88 +2.72%
LINK $12.95 +5.33%
HYPE $85.58 -2.54%
AAVE $132.19 -0.65%
SUI $0.8181 +2.84%
XLM $0.1920 +4.37%
ZEC $1,166.94 -1.56%
BTC $79,128.57 -0.62%
ETH $2,488.51 +0.15%
BNB $739.75 -1.04%
XRP $1.40 -0.93%
SOL $104.09 -1.85%
TRX $0.3340 -0.34%
DOGE $0.0902 +1.22%
ADA $0.2212 +1.47%
BCH $262.88 +2.72%
LINK $12.95 +5.33%
HYPE $85.58 -2.54%
AAVE $132.19 -0.65%
SUI $0.8181 +2.84%
XLM $0.1920 +4.37%
ZEC $1,166.94 -1.56%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

Связанные теги
Связанные теги
app_icon
ChainCatcher Building the Web3 world with innovations.