Scan to download
BTC $69,130.14 +3.01%
ETH $2,130.73 +3.68%
BNB $600.00 +1.16%
XRP $1.34 +2.17%
SOL $82.00 +1.93%
TRX $0.3175 -0.14%
DOGE $0.0925 +1.64%
ADA $0.2574 +4.57%
BCH $434.27 -1.32%
LINK $8.94 +3.55%
HYPE $36.84 +2.63%
AAVE $95.77 +1.77%
SUI $0.8918 +3.36%
XLM $0.1615 +0.36%
ZEC $253.41 +2.24%
BTC $69,130.14 +3.01%
ETH $2,130.73 +3.68%
BNB $600.00 +1.16%
XRP $1.34 +2.17%
SOL $82.00 +1.93%
TRX $0.3175 -0.14%
DOGE $0.0925 +1.64%
ADA $0.2574 +4.57%
BCH $434.27 -1.32%
LINK $8.94 +3.55%
HYPE $36.84 +2.63%
AAVE $95.77 +1.77%
SUI $0.8918 +3.36%
XLM $0.1615 +0.36%
ZEC $253.41 +2.24%

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

2026-03-13 11:57:56
Collection

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder stating that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft → attacker gains GitHub permissions → logs into ClawHub as a developer → publishes malicious Skills to implant backdoors → users download and install, executing malicious code leading to system intrusion.

app_icon
ChainCatcher Building the Web3 world with innovations.