Misty Fog Cosine: The OpenClaw 3.28 version may introduce a malicious axios dependency package

Gate News message: On March 31, Mumu Security founder Yu Xian issued a security warning stating that OpenClaw’s latest version 3.28 may introduce a poisoned axios dependency package, urging users to take care to check and investigate. Yu Xian noted that, in addition to the risks directly introduced by OpenClaw, the related Skills may also depend on axios, resulting in indirect poisoning. Because axios is widely used, a comprehensive investigation is recommended. It is reported that this poisoning incident was discovered in a timely manner.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
No comments