The AI development ecosystem is becoming a new target for security attacks.
Security experts from the blockchain security company SlowMist warn that the AI development platform ClawHub is at potential risk of a supply chain attack because it relies on GitHub accounts for login authentication.
Security analysis indicates that if attackers exploit GitHub credentials previously stolen by the Sha1-Hulud worm, they could gain developer access and log in to ClawHub.
The attack process may include:
- Phishing or malware to steal GitHub credentials
- Attackers gaining developer account access
- Logging into ClawHub as a developer
- Releasing a Skills plugin with a backdoor
- Users executing malicious code after downloading the plugin
Security researchers remind developers to enable multi-factor authentication and regularly check account permissions to reduce the risk of being attacked.