掃碼下載
BTC $64,168.93 +0.42%
ETH $1,677.91 -0.57%
BNB $609.79 +0.01%
XRP $1.13 +0.30%
SOL $68.25 +0.55%
TRX $0.3172 +1.18%
DOGE $0.0882 -2.14%
ADA $0.1742 +0.89%
BCH $208.37 +0.80%
LINK $8.00 +0.54%
HYPE $60.19 -0.08%
AAVE $67.06 +2.79%
SUI $0.7715 +1.12%
XLM $0.1893 -1.72%
ZEC $413.07 -4.04%
BTC $64,168.93 +0.42%
ETH $1,677.91 -0.57%
BNB $609.79 +0.01%
XRP $1.13 +0.30%
SOL $68.25 +0.55%
TRX $0.3172 +1.18%
DOGE $0.0882 -2.14%
ADA $0.1742 +0.89%
BCH $208.37 +0.80%
LINK $8.00 +0.54%
HYPE $60.19 -0.08%
AAVE $67.06 +2.79%
SUI $0.7715 +1.12%
XLM $0.1893 -1.72%
ZEC $413.07 -4.04%

慢霧:ClawHub 開發者請注意釣魚和憑據洩露風險

2026-03-13 11:57:56
收藏

ChainCatcher 消息,慢霧科技首席信息安全官 23pds 發文提醒稱,ClawHub 開發者請注意釣魚和憑據洩露風險。目前 ClawHub 依賴開發者 GitHub 一鍵登入,之前 Sha1-Hulud 蠕蟲竊取大量開發者的 GitHub 憑據,攻擊者可能會伺機攻擊 Skills。

攻擊路徑為:憑證竊取→攻擊者獲取 GitHub 權限→以開發者身份登入 ClawHub→發布惡意 Skills 植入後門→用戶下載安裝後執行惡意代碼導致系統入侵。

app_icon
ChainCatcher 與創新者共建Web3世界