掃碼下載
BTC $77,679.75 +5.12%
ETH $2,441.21 +6.13%
BNB $644.00 +4.29%
XRP $1.49 +6.42%
SOL $90.10 +6.44%
TRX $0.3248 -0.84%
DOGE $0.1008 +6.14%
ADA $0.2652 +7.32%
BCH $457.80 +5.10%
LINK $9.80 +6.56%
HYPE $44.77 +0.49%
AAVE $116.15 +10.68%
SUI $1.03 +7.64%
XLM $0.1734 +8.90%
ZEC $353.67 +4.14%
BTC $77,679.75 +5.12%
ETH $2,441.21 +6.13%
BNB $644.00 +4.29%
XRP $1.49 +6.42%
SOL $90.10 +6.44%
TRX $0.3248 -0.84%
DOGE $0.1008 +6.14%
ADA $0.2652 +7.32%
BCH $457.80 +5.10%
LINK $9.80 +6.56%
HYPE $44.77 +0.49%
AAVE $116.15 +10.68%
SUI $1.03 +7.64%
XLM $0.1734 +8.90%
ZEC $353.67 +4.14%

慢霧:ClawHub 開發者請注意釣魚和憑據洩露風險

2026-03-13 11:57:56
收藏

ChainCatcher 消息,慢霧科技首席信息安全官 23pds 發文提醒稱,ClawHub 開發者請注意釣魚和憑據洩露風險。目前 ClawHub 依賴開發者 GitHub 一鍵登入,之前 Sha1-Hulud 蠕蟲竊取大量開發者的 GitHub 憑據,攻擊者可能會伺機攻擊 Skills。

攻擊路徑為:憑證竊取→攻擊者獲取 GitHub 權限→以開發者身份登入 ClawHub→發布惡意 Skills 植入後門→用戶下載安裝後執行惡意代碼導致系統入侵。

app_icon
ChainCatcher 與創新者共建Web3世界