PANews reported on February 9th that, according to SlowMist monitoring, ClawHub, the official plugin center of the open-source AI agent project OpenClaw, is increasinglyPANews reported on February 9th that, according to SlowMist monitoring, ClawHub, the official plugin center of the open-source AI agent project OpenClaw, is increasingly

SlowMist: ClawHub is increasingly becoming a new target for attackers to poison supply chains.

2026/02/09 10:51
Okuma süresi: 1 dk

PANews reported on February 9th that, according to SlowMist monitoring, ClawHub, the official plugin center of the open-source AI agent project OpenClaw, is increasingly becoming a new target for attackers to carry out supply chain poisoning. Due to the platform's lack of a robust and rigorous review mechanism, a large number of malicious skills have been infiltrated and used to spread malicious code or deliver harmful content, posing potential security risks to developers and users. According to a report by Koi Security, 341 malicious skills were identified out of 2,857 scans, reflecting a typical "plugin/extension marketplace supply chain poisoning" pattern.

SlowMist recommends that you do not treat the "installation steps" in SKILL.md as a trusted source, and audit any commands that require copying and pasting. Be wary of prompts that ask for "system password/grant accessibility/system settings," as these are often points of escalation risk. Prioritize obtaining dependencies and tools from official channels and avoid executing installation scripts from unknown sources.

Piyasa Fırsatı
OpenClaw Logosu
OpenClaw Fiyatı(OPENCLAW)
$0.0002632
$0.0002632$0.0002632
-10.68%
USD
OpenClaw (OPENCLAW) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.