SlowMist Warns of Fake Job Campaign Targeting Web3 Developers
SlowMist analysts have reported a malicious campaign targeting Web3 developers through fake job offers on LinkedIn. Attackers pose as recruiters and send links to GitHub repositories containing hidden malware that steals wallet data and personal information.
Security researchers at SlowMist have uncovered a malicious campaign targeting Web3 developers through fake job offers on LinkedIn. The attackers impersonate recruiters and send links to GitHub repositories that appear to contain legitimate project code.
Hidden inside the files is a Node.js loader disguised as a Tailwind CSS plugin. The malware steals personal information, files, and cryptocurrency wallet data, executes remote commands, and monitors clipboard activity. Developers are advised to verify any unsolicited job offers and carefully review code before running it.
Source: ForkLog