A ClawHub plugin has been discovered covertly transforming AI assistants into cryptocurrency-earning "workers" for others. Ax Sharma, Research Lead at Manifold, identified that a user named "imaflytok" published 30 plugins, amassing around 9,800 downloads. These plugins, disguised as common utilities, secretly register AI assistants with third-party servers, generate cryptocurrency wallets, and hand over private keys without user consent. The plugins execute tasks every four hours, bypassing detection as they contain no malicious code, highlighting a significant oversight in plugin store review mechanisms.
ClawHub Plugin Exploits AI Assistants to Earn Cryptocurrency
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
