Slow Fog, ClawHub developers please be aware of phishing and credential leakage risks
Mar 13, 2026 11:57:56
The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.
The attack path is: credential theft β attacker gains GitHub permissions β logs into ClawHub as a developer β publishes malicious Skills to implant backdoors β users download and install, executing malicious code leading to system intrusion.
Latest News
ChainCatcher
Mar 17, 2026 18:37:37
ChainCatcher
Mar 17, 2026 18:32:56
ChainCatcher
Mar 17, 2026 18:22:59
ChainCatcher
Mar 17, 2026 18:01:54












