SlowMist Reports ClawHub Becoming Target for Supply Chain Poisoning Attacks

iconTechFlow
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
On-chain news reveals that SlowMist Security has uncovered a major supply chain poisoning attack targeting ClawHub, the plugin hub for the open-source AI Agent project OpenClaw. Attackers are injecting Base64-encoded malicious commands into SKILL.md files to steal passwords, gather system data, and upload files to external servers. A total of 341 malicious skills have been found, with infrastructure linked to the Poseidon hacker group. SlowMist's MistEye system has flagged 472 malicious skills and related IOCs. Users are urged to review all installation steps in SKILL.md files, avoid entering system passwords, and only source dependencies from verified origins. Inflation data remains a secondary concern for developers amid rising security risks.

SlowMist Security Team has discovered that the plugin center ClawHub of the open-source AI Agent project OpenClaw is currently suffering from a large-scale supply chain poisoning attack. Attackers have disguised "dependency installation / initialization" steps in the SKILL.md file, using Base64 encoding to hide malicious commands, implementing a "two-stage" attack chain. Security scans have identified 341 malicious skills. These malicious programs will phish user passwords, collect host information and documents, and upload data to the attacker's server. The related malicious infrastructure is associated with the Poseidon hacker group. Protection recommendations: • Audit all "installation steps" in SKILL.md • Be cautious of prompts requesting system passwords • Only obtain dependencies and tools from official channels SlowMist has issued a warning to customers through the MistEye system, involving 472 malicious skills and related IOCs.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.