BTC $79,410.00 -0.54%
ETH $2,498.25 +0.21%
BNB $746.05 -0.72%
XRP $1.41 -0.66%
SOL $105.20 -1.04%
TRX $0.3353 +0.08%
DOGE $0.0908 +1.47%
ADA $0.2227 +1.79%
BCH $260.47 +0.86%
LINK $13.21 +7.44%
HYPE $87.63 -1.35%
AAVE $133.29 -1.46%
SUI $0.8244 +3.71%
XLM $0.1926 +3.67%
ZEC $1,179.14 -0.89%
BTC $79,410.00 -0.54%
ETH $2,498.25 +0.21%
BNB $746.05 -0.72%
XRP $1.41 -0.66%
SOL $105.20 -1.04%
TRX $0.3353 +0.08%
DOGE $0.0908 +1.47%
ADA $0.2227 +1.79%
BCH $260.47 +0.86%
LINK $13.21 +7.44%
HYPE $87.63 -1.35%
AAVE $133.29 -1.46%
SUI $0.8244 +3.71%
XLM $0.1926 +3.67%
ZEC $1,179.14 -0.89%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.