Scan to download
BTC $59,216.79 -0.98%
ETH $1,581.72 +0.69%
BNB $549.39 -0.49%
XRP $1.04 -0.34%
SOL $73.63 +1.07%
TRX $0.3183 -1.71%
DOGE $0.0722 -0.59%
ADA $0.1444 -0.02%
BCH $199.79 +2.22%
LINK $7.26 -0.60%
HYPE $65.17 +4.25%
AAVE $89.41 -2.33%
SUI $0.6918 +0.67%
XLM $0.1796 +4.49%
ZEC $394.75 +3.55%
BTC $59,216.79 -0.98%
ETH $1,581.72 +0.69%
BNB $549.39 -0.49%
XRP $1.04 -0.34%
SOL $73.63 +1.07%
TRX $0.3183 -1.71%
DOGE $0.0722 -0.59%
ADA $0.1444 -0.02%
BCH $199.79 +2.22%
LINK $7.26 -0.60%
HYPE $65.17 +4.25%
AAVE $89.41 -2.33%
SUI $0.6918 +0.67%
XLM $0.1796 +4.49%
ZEC $394.75 +3.55%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56
Collection

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.