[Subscribe Now] Track A-Level Transparency Project Biweekly Report and Discover the Top 1% of Projects
API Download the RootData App

Slow Fog, ClawHub developers please be aware of phishing and credential leakage risks

Mar 13, 2026 11:57:56

Share to

The Chief Information Security Officer of Slow Fog Technology, 23pds, issued a reminder that ClawHub developers should be aware of phishing and credential leakage risks. Currently, ClawHub relies on developers' GitHub one-click login. Previously, the Sha1-Hulud worm stole a large number of developers' GitHub credentials, and attackers may take the opportunity to attack Skills.

The attack path is: credential theft β†’ attacker gains GitHub permissions β†’ logs into ClawHub as a developer β†’ publishes malicious Skills to implant backdoors β†’ users download and install, executing malicious code leading to system intrusion.

Recent Fundraising

More
$10M Mar 17
$52M Mar 17
$255M Mar 16

New Tokens

More
Mar 13
Mar 11
Mar 8

Latest Updates on 𝕏

More