掃碼下載
BTC $76,313.25 -1.39%
ETH $2,287.69 -0.77%
BNB $624.55 -0.36%
XRP $1.38 -1.30%
SOL $83.99 -0.86%
TRX $0.3229 -0.75%
DOGE $0.0994 +0.66%
ADA $0.2466 -0.64%
BCH $452.71 +0.30%
LINK $9.24 -0.78%
HYPE $40.03 -4.09%
AAVE $96.40 -1.16%
SUI $0.9246 -1.12%
XLM $0.1618 -2.38%
ZEC $335.88 -5.00%
BTC $76,313.25 -1.39%
ETH $2,287.69 -0.77%
BNB $624.55 -0.36%
XRP $1.38 -1.30%
SOL $83.99 -0.86%
TRX $0.3229 -0.75%
DOGE $0.0994 +0.66%
ADA $0.2466 -0.64%
BCH $452.71 +0.30%
LINK $9.24 -0.78%
HYPE $40.03 -4.09%
AAVE $96.40 -1.16%
SUI $0.9246 -1.12%
XLM $0.1618 -2.38%
ZEC $335.88 -5.00%

慢霧:ClawHub 開發者請注意釣魚和憑據洩露風險

2026-03-13 11:57:56
收藏

ChainCatcher 消息,慢霧科技首席信息安全官 23pds 發文提醒稱,ClawHub 開發者請注意釣魚和憑據洩露風險。目前 ClawHub 依賴開發者 GitHub 一鍵登入,之前 Sha1-Hulud 蠕蟲竊取大量開發者的 GitHub 憑據,攻擊者可能會伺機攻擊 Skills。

攻擊路徑為:憑證竊取→攻擊者獲取 GitHub 權限→以開發者身份登入 ClawHub→發布惡意 Skills 植入後門→用戶下載安裝後執行惡意代碼導致系統入侵。

app_icon
ChainCatcher 與創新者共建Web3世界