🚨 THE #1 AI SKILL ON OPENCLAW WAS LITERALLY MALWARE.


THE AI REVOLUTION JUST FACED A CATASTROPHIC SUPPLY CHAIN ATTACK.
1,184 MALICIOUS PLUGINS FLOODED THE CLAWHUB MARKETPLACE.
THE BREAKDOWN OF THE CLAWHAVOC CAMPAIGN IS BRUTAL:
THE ONLY BARRIER TO PUBLISH A SKILL WAS A 1-WEEK-OLD GITHUB ACCOUNT.
ATTACKERS UPLOADED PACKAGES DISGUISED AS CRYPTO BOTS, WALLET TRACKERS, AND YOUTUBE TOOLS.
THE FLAWLESS DOCUMENTATION IN THE FILES TRICKED USERS INTO RUNNING A SINGLE TERMINAL COMMAND.
THAT COMMAND DROPPED ATOMIC STEALER ON MACOS.
IT INSTANTLY STRIPPED BROWSER PASSWORDS, SSH KEYS, CRYPTO WALLETS, AND EVERY API KEY SITTING IN YOUR .ENV FILES.
ON OTHER SYSTEMS, IT OPENED A REVERSE SHELL GIVING THE ATTACKER FULL ROOT CONTROL.
CISCO SCANNED THE TOP-RANKED "WHAT WOULD ELON DO?" SKILL.
IT HAD 9 VULNERABILITIES, INCLUDING 2 CRITICAL FLAWS.
IT USED PROMPT INJECTION TO BYPASS SAFETY RULES AND SILENTLY EXFILTRATE DATA.
THIS IS THE NPM SUPPLY CHAIN NIGHTMARE ON STEROIDS.
EXCEPT NOW, THE MALWARE CAN ACTUALLY THINK.
post-image
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)