掃碼下載
BTC $76,183.60 -2.04%
ETH $2,271.16 -1.94%
BNB $621.37 -0.84%
XRP $1.38 -1.88%
SOL $83.42 -2.08%
TRX $0.3235 -0.58%
DOGE $0.0985 +0.17%
ADA $0.2461 -0.52%
BCH $446.64 -0.70%
LINK $9.19 -1.17%
HYPE $39.94 -5.68%
AAVE $96.42 +0.18%
SUI $0.9196 -1.14%
XLM $0.1620 -3.36%
ZEC $333.15 -6.76%
BTC $76,183.60 -2.04%
ETH $2,271.16 -1.94%
BNB $621.37 -0.84%
XRP $1.38 -1.88%
SOL $83.42 -2.08%
TRX $0.3235 -0.58%
DOGE $0.0985 +0.17%
ADA $0.2461 -0.52%
BCH $446.64 -0.70%
LINK $9.19 -1.17%
HYPE $39.94 -5.68%
AAVE $96.42 +0.18%
SUI $0.9196 -1.14%
XLM $0.1620 -3.36%
ZEC $333.15 -6.76%

慢霧:ClawHub 開發者請注意釣魚和憑據洩露風險

2026-03-13 11:57:56
收藏

ChainCatcher 消息,慢霧科技首席信息安全官 23pds 發文提醒稱,ClawHub 開發者請注意釣魚和憑據洩露風險。目前 ClawHub 依賴開發者 GitHub 一鍵登入,之前 Sha1-Hulud 蠕蟲竊取大量開發者的 GitHub 憑據,攻擊者可能會伺機攻擊 Skills。

攻擊路徑為:憑證竊取→攻擊者獲取 GitHub 權限→以開發者身份登入 ClawHub→發布惡意 Skills 植入後門→用戶下載安裝後執行惡意代碼導致系統入侵。

app_icon
ChainCatcher 與創新者共建Web3世界