掃碼下載
BTC $62,538.94 +2.56%
ETH $1,633.28 +4.07%
BNB $593.04 +2.96%
XRP $1.13 +5.21%
SOL $65.06 +3.87%
TRX $0.3289 +2.97%
DOGE $0.0849 +4.52%
ADA $0.1652 +5.41%
BCH $226.66 +1.76%
LINK $7.77 +5.88%
HYPE $59.19 -0.13%
AAVE $63.79 +3.85%
SUI $0.7601 +8.08%
XLM $0.2055 +2.80%
ZEC $397.26 +8.81%
BTC $62,538.94 +2.56%
ETH $1,633.28 +4.07%
BNB $593.04 +2.96%
XRP $1.13 +5.21%
SOL $65.06 +3.87%
TRX $0.3289 +2.97%
DOGE $0.0849 +4.52%
ADA $0.1652 +5.41%
BCH $226.66 +1.76%
LINK $7.77 +5.88%
HYPE $59.19 -0.13%
AAVE $63.79 +3.85%
SUI $0.7601 +8.08%
XLM $0.2055 +2.80%
ZEC $397.26 +8.81%

慢霧:ClawHub 開發者請注意釣魚和憑據洩露風險

2026-03-13 11:57:56
收藏

ChainCatcher 消息,慢霧科技首席信息安全官 23pds 發文提醒稱,ClawHub 開發者請注意釣魚和憑據洩露風險。目前 ClawHub 依賴開發者 GitHub 一鍵登入,之前 Sha1-Hulud 蠕蟲竊取大量開發者的 GitHub 憑據,攻擊者可能會伺機攻擊 Skills。

攻擊路徑為:憑證竊取→攻擊者獲取 GitHub 權限→以開發者身份登入 ClawHub→發布惡意 Skills 植入後門→用戶下載安裝後執行惡意代碼導致系統入侵。

app_icon
ChainCatcher 與創新者共建Web3世界