BTC $83,396.28 -1.24%
ETH $2,685.84 +0.07%
BNB $764.06 -1.96%
XRP $1.49 -2.12%
SOL $118.52 -3.30%
TRX $0.3353 +0.52%
DOGE $0.0941 -3.46%
ADA $0.2484 -3.30%
BCH $309.74 -6.24%
LINK $15.58 +10.38%
HYPE $86.88 -4.51%
AAVE $149.06 -3.80%
SUI $1.14 -9.05%
XLM $0.2292 +5.19%
ZEC $1,483.11 -6.41%
AAPL $338.08 -0.65%
AMZN $246.35 -1.24%
GOOGL $342.28 -0.37%
MSFT $508.94 -1.21%
META $717.59 -3.08%
NVDA $228.67 +1.54%
TSLA $357.71 -3.83%
SNDK $1,706.92 -3.02%
INTC $115.44 -5.80%
SPCX $146.01 -2.47%
MU $1,051.99 -2.77%
AMD $608.03 -3.71%
BTC $83,396.28 -1.24%
ETH $2,685.84 +0.07%
BNB $764.06 -1.96%
XRP $1.49 -2.12%
SOL $118.52 -3.30%
TRX $0.3353 +0.52%
DOGE $0.0941 -3.46%
ADA $0.2484 -3.30%
BCH $309.74 -6.24%
LINK $15.58 +10.38%
HYPE $86.88 -4.51%
AAVE $149.06 -3.80%
SUI $1.14 -9.05%
XLM $0.2292 +5.19%
ZEC $1,483.11 -6.41%
AAPL $338.08 -0.65%
AMZN $246.35 -1.24%
GOOGL $342.28 -0.37%
MSFT $508.94 -1.21%
META $717.59 -3.08%
NVDA $228.67 +1.54%
TSLA $357.71 -3.83%
SNDK $1,706.92 -3.02%
INTC $115.44 -5.80%
SPCX $146.01 -2.47%
MU $1,051.99 -2.77%
AMD $608.03 -3.71%

Slow Fog: ClawHub is gradually becoming a new target for attackers to implement supply chain poisoning

2026-02-09 10:53:52

According to SlowMist's monitoring, the official plugin center ClawHub of the open-source AI Agent project OpenClaw is gradually becoming a new target for attackers to implement supply chain poisoning.

Due to the platform's lack of a comprehensive and strict review mechanism, a large number of malicious skills have already infiltrated, being used to spread malicious code or deliver harmful content, posing potential security risks to developers and users. According to a report by Koi Security, 341 malicious skills were identified in a scan of 2,857 skills, reflecting a typical "plugin/extension market supply chain poisoning" pattern.

SlowMist advises not to treat the "installation steps" in SKILL.md as a trusted source; any command that requires copying and pasting should be audited first; be wary of prompts that "require entering the system password/granting accessibility/system settings," as these are often points of risk escalation; prioritize obtaining dependencies and tools from official channels to avoid executing installation scripts from unknown sources.

app_icon
ChainCatcher Building the Web3 world with innovations.