扫码下载
BTC $60,973.98 -3.91%
ETH $1,573.49 -10.65%
BNB $572.92 -4.57%
XRP $1.09 -5.86%
SOL $63.52 -7.06%
TRX $0.3204 -3.46%
DOGE $0.0813 -7.19%
ADA $0.1568 -13.05%
BCH $209.83 -13.70%
LINK $7.36 -7.18%
HYPE $59.32 -7.24%
AAVE $62.70 -11.30%
SUI $0.6967 -8.76%
XLM $0.2007 +0.31%
ZEC $380.95 -15.79%
BTC $60,973.98 -3.91%
ETH $1,573.49 -10.65%
BNB $572.92 -4.57%
XRP $1.09 -5.86%
SOL $63.52 -7.06%
TRX $0.3204 -3.46%
DOGE $0.0813 -7.19%
ADA $0.1568 -13.05%
BCH $209.83 -13.70%
LINK $7.36 -7.18%
HYPE $59.32 -7.24%
AAVE $62.70 -11.30%
SUI $0.6967 -8.76%
XLM $0.2007 +0.31%
ZEC $380.95 -15.79%

慢雾:ClawHub 开发者请注意钓鱼和凭据泄露风险

2026-03-13 11:57:56
收藏

ChainCatcher 消息,慢雾科技首席信息安全官 23pds 发文提醒称,ClawHub 开发者请注意钓鱼和凭据泄露风险。目前 ClawHub 依赖开发者 GitHub 一键登录,之前 Sha1-Hulud 蠕虫窃取大量开发者的 GitHub 凭据,攻击者可能会伺机攻击 Skills。

攻击路径为:凭证窃取→攻击者获取 GitHub 权限→以开发者身份登录 ClawHub→发布恶意 Skills 植入后门→用户下载安装后执行恶意代码导致系统入侵。

app_icon
ChainCatcher 与创新者共建Web3世界