Scam Alert: Fake GitHub Airdrop Targets CLAW Token Users

Scam Details
A fake GitHub airdrop scam is targeting users with promises of $CLAW tokens for GitHub contributions. According to the source, the scam operates through the following mechanism:
- Users receive messages claiming they've been "selected" for a $CLAW airdrop based on their GitHub activity
- The scam directs users to connect their wallets through a random Google share link
- This Google link redirects to a shady .xyz website
- The fake GitHub discussion where users get tagged and receive GitHub emails is at:
https://github.com/highwayskinkjump/OpenClawEco-4828884/discussions/7
Security Warning
This is identified as a wallet-draining phishing scam. The source explicitly warns:
- Do NOT connect your wallet to any links from this scam
- Do NOT sign any transactions or approvals
- The use of a Google share link followed by redirection to a .xyz domain is a common phishing tactic
GitHub-based airdrop scams typically work by creating fake repositories or discussions that appear legitimate, then using GitHub's notification system to reach potential victims. Once users connect their wallets through the provided link, the scam site can request permissions that allow attackers to drain funds.
📖 Read the full source: r/openclaw
👀 See Also

Litellm PyPI Package Compromised: Malicious Version 1.82.8 Exfiltrated Credentials
The litellm PyPI package, which unifies calls to OpenAI, Anthropic, Cohere and other LLM providers, was compromised with malicious version 1.82.8 that exfiltrated SSH keys, cloud credentials, API keys, and other sensitive data for about an hour.

Axios 1.14.1 compromised with malware, targets AI-assisted development workflows
Axios version 1.14.1 has been compromised in a supply chain attack that silently pulls in [email protected], an obfuscated RAT dropper. Developers using AI coding assistants like Claude should immediately check their lockfiles and machines for infection.

MCP Package Security Scan Reveals Widespread Destructive Capabilities Without Confirmation
A security scan of 2,386 MCP packages on npm found 63.5% expose destructive operations like file deletion and database drops without requiring human confirmation. The researcher discovered 49% had security issues overall, with 402 critical and 240 high severity vulnerabilities.

OpenClaw Slack Security: API Key Exposure Risks and Fixes
OpenClaw Slack deployments can expose API keys through error messages in channels, with over 8,000 instances found exposed in a Bitsight report. The source details three specific vulnerabilities and provides practical fixes including system prompt modifications and SlackClaw migration.