市值: $2.1514T -0.57%
體積(24小時): $43.9992B 8.09%
  • 市值: $2.1514T -0.57%
  • 體積(24小時): $43.9992B 8.09%
  • 恐懼與貪婪指數:
  • 市值: $2.1514T -0.57%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密貨幣新聞文章

ClawHub 遭到圍攻:數千個插件在復雜的人工智能攻擊中受到損害

2026/02/09 16:49

OpenClaw AI 代理生態系統遭遇重大安全漏洞,官方插件商店 ClawHub 被發現託管數百個惡意插件。這種複雜的人工智能攻擊凸顯了關鍵漏洞。

ClawHub 遭到圍攻:數千個插件在復雜的人工智能攻擊中受到損害

ClawHub Under Siege: Thousands of Plugins Compromised in Sophisticated AI Attack

ClawHub 遭到圍攻:數千個插件在復雜的人工智能攻擊中受到損害

A significant security incident has rocked the rapidly expanding AI agent ecosystem, with the official plugin store for the popular open-source project OpenClaw, known as ClawHub, being compromised. Cybersecurity firm SlowMist has issued a stark warning, revealing that hundreds of malicious plugins were uploaded to the platform, posing a severe threat to users.

一起重大安全事件震撼了快速擴張的人工智能代理生態系統,流行的開源項目 OpenClaw 的官方插件商店(稱為 ClawHub)遭到破壞。網絡安全公司慢霧發布了嚴厲警告,稱數百個惡意插件被上傳到該平台,對用戶構成嚴重威脅。

The Anatomy of the Attack

攻擊的剖析

The attack exploited a critical flaw in ClawHub's review process, allowing seemingly harmless plugins, presented as setup or helper tools, to contain hidden malware. Researchers from SlowMist and Koi Security identified that these malicious plugins, which constituted a staggering 12% of scanned plugins according to Koi Security's analysis of 2,857 plugins, were designed to surreptitiously siphon user data upon installation.

該攻擊利用了 ClawHub 審查過程中的一個關鍵缺陷,允許看似無害的插件(以安裝或幫助工具的形式出現)包含隱藏的惡意軟件。 SlowMist 和 Koi Security 的研究人員發現,根據 Koi Security 對 2,857 個插件的分析,這些惡意插件佔掃描插件的比例高達 12%,其設計目的是在安裝後秘密竊取用戶數據。

Attackers ingeniously targeted SKILL.md files, which are intended to provide installation instructions. Instead of just text, these files embedded dubious commands, cleverly disguised using Base64 encoding, curl-to-bash scripts, and two-step malware loaders to evade detection. These commands mimicked normal setup tasks, tricking users into unknowingly executing malware.

攻擊者巧妙地瞄準了旨在提供安裝說明的 SKILL.md 文件。這些文件不僅僅是文本,還嵌入了可疑命令,並使用 Base64 編碼、curl-to-bash 腳本和兩步惡意軟件加載程序巧妙地進行偽裝,以逃避檢測。這些命令模仿正常的安裝任務,誘騙用戶在不知不覺中執行惡意軟件。

Tracing the Malicious Infrastructure

追踪惡意基礎設施

Analysis revealed that over 400 malicious plugins were communicating with a small cluster of suspicious websites and IP addresses. One notable IP address, 91.92.242.30, has historical ties to cyber-crime and extortion groups, while socifiapp.com, a recently registered domain, served as a remote control server for the malware. The fake plugins often adopted attractive themes such as crypto, finance, software updates, and security tools, further lulling developers into a false sense of security. For instance, a plugin named "X (Twitter) Trends" appeared benign but secretly installed data-stealing malware.

分析顯示,超過 400 個惡意插件正在與一小群可疑網站和 IP 地址進行通信。一個值得注意的 IP 地址 91.92.242.30 與網絡犯罪和勒索團體有著歷史聯繫,而最近註冊的域名 socifiapp.com 則充當了惡意軟件的遠程控制服務器。假冒插件通常採用加密、金融、軟件更新和安全工具等有吸引力的主題,進一步讓開發人員陷入錯誤的安全感。例如,一個名為“X (Twitter) Trends”的插件看似良性,但卻秘密安裝了數據竊取惡意軟件。

The Broader Implications for AI Ecosystems

對人工智能生態系統的更廣泛影響

SlowMist has been actively monitoring plugin marketplaces, having detected and flagged 472 malicious plugins. This incident underscores a broader, systemic risk within the entire plugin ecosystem, particularly concerning "instruction files that actually run harmful code." The company emphasizes the need for platforms and users to remain vigilant, looking out for warning signs such as multi-step file downloads, consistent server or IP usage across plugins, and direct IP address connections in commands.

SlowMist 一直在積極監控插件市場,已檢測並標記了 472 個惡意插件。這一事件凸顯了整個插件生態系統中更廣泛的系統性風險,特別是涉及“實際運行有害代碼的指令文件”。該公司強調平台和用戶需要保持警惕,留意警告信號,例如多步驟文件下載、跨插件的一致服務器或 IP 使用以及命令中的直接 IP 地址連接。

Staying Safe in the Age of AI Plugins

在人工智能插件時代保持安全

To mitigate risks, users are strongly advised to scrutinize installation instructions before execution and to avoid copy-pasting commands without full comprehension. Sudden requests for passwords or permissions should also be treated as red flags. Downloading tools exclusively from reputable and official sources, rather than from untrusted scripts, is paramount for maintaining security. It seems the digital world, much like a bustling New York street, always has a few unexpected twists and turns, so stay sharp out there!

為了降低風險,強烈建議用戶在執行之前仔細檢查安裝說明,並避免在沒有完全理解的情況下複製粘貼命令。突然請求密碼或權限也應視為危險信號。僅從信譽良好的官方來源下載工具,而不是從不受信任的腳本下載工具,對於維護安全性至關重要。數字世界似乎就像熙熙攘攘的紐約街道一樣,總是有一些意想不到的曲折,所以要保持敏銳!

原始來源:namecoinnews

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年08月04日 其他文章發表於