Scan to download
BTC $79,084.50 -2.78%
ETH $2,219.92 -3.23%
BNB $673.53 -0.90%
XRP $1.43 -4.20%
SOL $89.26 -3.57%
TRX $0.3517 -0.67%
DOGE $0.1133 -2.20%
ADA $0.2610 -4.08%
BCH $425.38 -2.67%
LINK $10.05 -4.78%
HYPE $44.19 +0.81%
AAVE $92.75 -6.95%
SUI $1.09 -8.13%
XLM $0.1543 -5.67%
ZEC $515.79 -6.50%
BTC $79,084.50 -2.78%
ETH $2,219.92 -3.23%
BNB $673.53 -0.90%
XRP $1.43 -4.20%
SOL $89.26 -3.57%
TRX $0.3517 -0.67%
DOGE $0.1133 -2.20%
ADA $0.2610 -4.08%
BCH $425.38 -2.67%
LINK $10.05 -4.78%
HYPE $44.19 +0.81%
AAVE $92.75 -6.95%
SUI $1.09 -8.13%
XLM $0.1543 -5.67%
ZEC $515.79 -6.50%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56
Collection

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.