ClawHub developers are being cautioned about potential phishing and credential leak risks. According to PANews, 23pds, the Chief Information Security Officer at SlowMist Technology, highlighted concerns regarding the security of ClawHub's reliance on GitHub for one-click login. Previously, the Sha1-Hulud worm had stolen numerous GitHub credentials from developers, posing a threat of further attacks on Skills.
The attack pathway involves credential theft, granting attackers GitHub access, allowing them to log into ClawHub as developers, and subsequently publishing malicious Skills with embedded backdoors. Once users download and install these, they may execute malicious code, leading to system intrusions.