ME News reports that on February (UTC+8), according to GoPlus monitoring data, the skill "What Would Elon Do," which once topped the ClawHub download charts, is actually a Trojan. Malicious actors used bots to increase traffic volume, manipulated ratings and other means to promote it to popularity, encouraging a large number of users to install it.



After installation, this malicious skill will steal users' SSH keys, private keys of crypto wallets, and browser cookies, as well as install a backdoor on the attacker's server, which has already led to actual user asset losses. This incident revealed a serious new type of supply chain attack in the Skill ecosystem. GoPlus reminds users that OpenClaw should not be run without protection.

Additionally, according to chiefofautism, a total of 1184 malicious skills were found on the ClawHub market, of which 677 malicious packages were uploaded by a single attacker.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)