Scan to download
BTC $78,074.70 -0.04%
ETH $2,322.59 -1.13%
BNB $628.04 -0.74%
XRP $1.41 -1.34%
SOL $85.52 -1.03%
TRX $0.3262 +0.79%
DOGE $0.0990 +0.12%
ADA $0.2482 -1.82%
BCH $454.74 +0.57%
LINK $9.35 -1.37%
HYPE $42.84 +3.89%
AAVE $98.95 +3.46%
SUI $0.9382 -0.96%
XLM $0.1679 -2.20%
ZEC $360.29 +1.58%
BTC $78,074.70 -0.04%
ETH $2,322.59 -1.13%
BNB $628.04 -0.74%
XRP $1.41 -1.34%
SOL $85.52 -1.03%
TRX $0.3262 +0.79%
DOGE $0.0990 +0.12%
ADA $0.2482 -1.82%
BCH $454.74 +0.57%
LINK $9.35 -1.37%
HYPE $42.84 +3.89%
AAVE $98.95 +3.46%
SUI $0.9382 -0.96%
XLM $0.1679 -2.20%
ZEC $360.29 +1.58%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56
Collection

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.