시가총액: $2.2006T 0.82%
거래량(24시간): $38.5475B -31.41%
  • 시가총액: $2.2006T 0.82%
  • 거래량(24시간): $38.5475B -31.41%
  • 공포와 탐욕 지수:
  • 시가총액: $2.2006T 0.82%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

ClawHub Under Siege: 정교한 AI 공격으로 수천 개의 플러그인이 손상됨

2026/02/09 16:49

공식 플러그인 스토어인 ClawHub에서 수백 개의 악성 플러그인을 호스팅하는 것으로 밝혀지면서 OpenClaw AI 에이전트 생태계에 심각한 보안 침해가 발생했습니다. 이 정교한 AI 공격은 심각한 취약점을 드러냅니다.

ClawHub Under Siege: 정교한 AI 공격으로 수천 개의 플러그인이 손상됨

ClawHub Under Siege: Thousands of Plugins Compromised in Sophisticated AI Attack

ClawHub Under Siege: 정교한 AI 공격으로 수천 개의 플러그인이 손상됨

A significant security incident has rocked the rapidly expanding AI agent ecosystem, with the official plugin store for the popular open-source project OpenClaw, known as ClawHub, being compromised. Cybersecurity firm SlowMist has issued a stark warning, revealing that hundreds of malicious plugins were uploaded to the platform, posing a severe threat to users.

ClawHub로 알려진 인기 오픈 소스 프로젝트 OpenClaw의 공식 플러그인 스토어가 손상되면서 심각한 보안 사고가 빠르게 확장되고 있는 AI 에이전트 생태계를 뒤흔들었습니다. 사이버 보안 회사인 SlowMist는 수백 개의 악성 플러그인이 플랫폼에 업로드되어 사용자에게 심각한 위협을 가하고 있음을 밝히며 엄중한 경고를 발표했습니다.

The Anatomy of the Attack

공격 분석

The attack exploited a critical flaw in ClawHub's review process, allowing seemingly harmless plugins, presented as setup or helper tools, to contain hidden malware. Researchers from SlowMist and Koi Security identified that these malicious plugins, which constituted a staggering 12% of scanned plugins according to Koi Security's analysis of 2,857 plugins, were designed to surreptitiously siphon user data upon installation.

이 공격은 ClawHub의 검토 프로세스에 있는 심각한 결함을 악용하여 설정 또는 도우미 도구로 제공되는 무해해 보이는 플러그인에 숨겨진 악성 코드를 포함할 수 있도록 했습니다. SlowMist와 Koi Security의 연구원들은 Koi Security가 2,857개의 플러그인을 분석한 결과 검색된 플러그인 중 무려 12%를 차지하는 이러한 악성 플러그인이 설치 시 은밀하게 사용자 데이터를 빼돌리도록 설계되었음을 확인했습니다.

Attackers ingeniously targeted SKILL.md files, which are intended to provide installation instructions. Instead of just text, these files embedded dubious commands, cleverly disguised using Base64 encoding, curl-to-bash scripts, and two-step malware loaders to evade detection. These commands mimicked normal setup tasks, tricking users into unknowingly executing malware.

공격자들은 설치 지침을 제공하기 위한 SKILL.md 파일을 교묘하게 표적으로 삼았습니다. 단순한 텍스트 대신 이러한 파일에는 감지를 회피하기 위해 Base64 인코딩, 컬-배시(curl-to-bash) 스크립트 및 2단계 악성 코드 로더를 사용하여 교묘하게 위장한 모호한 명령이 포함되어 있었습니다. 이러한 명령은 일반적인 설정 작업을 모방하여 사용자가 자신도 모르게 악성 코드를 실행하도록 속였습니다.

Tracing the Malicious Infrastructure

악성 인프라 추적

Analysis revealed that over 400 malicious plugins were communicating with a small cluster of suspicious websites and IP addresses. One notable IP address, 91.92.242.30, has historical ties to cyber-crime and extortion groups, while socifiapp.com, a recently registered domain, served as a remote control server for the malware. The fake plugins often adopted attractive themes such as crypto, finance, software updates, and security tools, further lulling developers into a false sense of security. For instance, a plugin named "X (Twitter) Trends" appeared benign but secretly installed data-stealing malware.

분석 결과 400개 이상의 악성 플러그인이 의심스러운 웹사이트 및 IP 주소로 구성된 소규모 클러스터와 통신하고 있는 것으로 나타났습니다. 주목할만한 IP 주소 중 하나인 91.92.242.30은 사이버 범죄 및 강탈 그룹과 역사적으로 연관되어 있으며, 최근 등록된 도메인인 socifiapp.com은 악성 코드의 원격 제어 서버 역할을 했습니다. 가짜 플러그인은 종종 암호화폐, 금융, 소프트웨어 업데이트, 보안 도구와 같은 매력적인 테마를 채택하여 개발자를 잘못된 보안 감각에 빠지게 만들었습니다. 예를 들어, "X(Twitter) Trends"라는 플러그인은 겉으로는 무해해 보이지만 비밀리에 설치된 데이터 도용 악성 코드입니다.

The Broader Implications for AI Ecosystems

AI 생태계에 대한 더 넓은 의미

SlowMist has been actively monitoring plugin marketplaces, having detected and flagged 472 malicious plugins. This incident underscores a broader, systemic risk within the entire plugin ecosystem, particularly concerning "instruction files that actually run harmful code." The company emphasizes the need for platforms and users to remain vigilant, looking out for warning signs such as multi-step file downloads, consistent server or IP usage across plugins, and direct IP address connections in commands.

SlowMist는 플러그인 마켓플레이스를 적극적으로 모니터링하여 472개의 악성 플러그인을 탐지하고 표시했습니다. 이 사건은 특히 "실제로 유해한 코드를 실행하는 명령 파일"과 관련하여 전체 플러그인 생태계 내에서 더 광범위하고 체계적인 위험을 강조합니다. 회사는 플랫폼과 사용자가 경계심을 유지하고 다단계 파일 다운로드, 플러그인 전체의 일관된 서버 또는 IP 사용, 명령의 직접 IP 주소 연결과 같은 경고 신호를 주의 깊게 살펴야 할 필요성을 강조합니다.

Staying Safe in the Age of AI Plugins

AI 플러그인 시대의 안전 유지

To mitigate risks, users are strongly advised to scrutinize installation instructions before execution and to avoid copy-pasting commands without full comprehension. Sudden requests for passwords or permissions should also be treated as red flags. Downloading tools exclusively from reputable and official sources, rather than from untrusted scripts, is paramount for maintaining security. It seems the digital world, much like a bustling New York street, always has a few unexpected twists and turns, so stay sharp out there!

위험을 완화하려면 사용자는 실행하기 전에 설치 지침을 면밀히 조사하고 완전히 이해하지 못한 채 명령을 복사하여 붙여넣는 것을 피하는 것이 좋습니다. 비밀번호나 권한에 대한 갑작스러운 요청도 위험 신호로 간주되어야 합니다. 신뢰할 수 없는 스크립트가 아닌 평판이 좋고 공식적인 소스에서만 도구를 다운로드하는 것이 보안을 유지하는 데 가장 중요합니다. 번화한 뉴욕의 거리와 마찬가지로 디지털 세계에는 항상 예상치 못한 우여곡절이 있는 것 같으니, 정신을 차려야 합니다!

원본 소스:namecoinnews

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年07月27日 에 게재된 다른 기사