BTC $62,700.00 -1.81%
ETH $1,869.23 -1.26%
BNB $604.46 -0.87%
XRP $1.00 -0.46%
SOL $75.28 -1.52%
TRX $0.3326 -0.56%
DOGE $0.0695 -0.94%
ADA $0.1785 -3.35%
BCH $200.36 -6.16%
LINK $8.80 -0.31%
HYPE $55.58 -4.44%
AAVE $85.68 -3.32%
SUI $0.6758 -2.42%
XLM $0.1598 -0.64%
ZEC $482.74 -2.48%
BTC $62,700.00 -1.81%
ETH $1,869.23 -1.26%
BNB $604.46 -0.87%
XRP $1.00 -0.46%
SOL $75.28 -1.52%
TRX $0.3326 -0.56%
DOGE $0.0695 -0.94%
ADA $0.1785 -3.35%
BCH $200.36 -6.16%
LINK $8.80 -0.31%
HYPE $55.58 -4.44%
AAVE $85.68 -3.32%
SUI $0.6758 -2.42%
XLM $0.1598 -0.64%
ZEC $482.74 -2.48%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.