BTC $64,823.32 +1.36%
ETH $1,920.91 +1.42%
BNB $591.87 +4.19%
XRP $1.08 +1.90%
SOL $74.62 +1.97%
TRX $0.3291 +0.94%
DOGE $0.0704 +0.32%
ADA $0.1712 +4.79%
BCH $220.87 +5.10%
LINK $8.48 +2.56%
HYPE $54.67 -0.04%
AAVE $99.83 +1.10%
SUI $0.7007 +2.53%
XLM $0.1724 +0.23%
ZEC $474.49 +2.07%
BTC $64,823.32 +1.36%
ETH $1,920.91 +1.42%
BNB $591.87 +4.19%
XRP $1.08 +1.90%
SOL $74.62 +1.97%
TRX $0.3291 +0.94%
DOGE $0.0704 +0.32%
ADA $0.1712 +4.79%
BCH $220.87 +5.10%
LINK $8.48 +2.56%
HYPE $54.67 -0.04%
AAVE $99.83 +1.10%
SUI $0.7007 +2.53%
XLM $0.1724 +0.23%
ZEC $474.49 +2.07%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56
Collection

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.