Scan to download
BTC $60,838.54 +0.80%
ETH $1,559.15 -2.67%
BNB $575.13 -1.38%
XRP $1.10 -0.67%
SOL $62.66 -3.62%
TRX $0.3207 -1.01%
DOGE $0.0820 -1.26%
ADA $0.1602 -0.62%
BCH $218.19 -0.31%
LINK $7.41 -0.48%
HYPE $58.66 -5.18%
AAVE $61.21 -2.56%
SUI $0.7221 +2.67%
XLM $0.2033 +6.49%
ZEC $354.92 +6.80%
BTC $60,838.54 +0.80%
ETH $1,559.15 -2.67%
BNB $575.13 -1.38%
XRP $1.10 -0.67%
SOL $62.66 -3.62%
TRX $0.3207 -1.01%
DOGE $0.0820 -1.26%
ADA $0.1602 -0.62%
BCH $218.19 -0.31%
LINK $7.41 -0.48%
HYPE $58.66 -5.18%
AAVE $61.21 -2.56%
SUI $0.7221 +2.67%
XLM $0.2033 +6.49%
ZEC $354.92 +6.80%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56
Collection

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.